Out-of-bounds read in Linux kernel - CVE-2026-98089
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to read out-of-bounds memory.
The vulnerability exists due to an uninitialized transport header offset causing an out-of-bounds read in alb_determine_nd() in the bonding driver when inspecting ICMPv6 headers in IPv6 packets on bonding transmit paths. A remote attacker can send an IPv6 packet that is processed through a bonding transmit path to read out-of-bounds memory.
The affected paths include packets sent through AF_PACKET or raw sockets and forwarded packets.