Function Call with Incorrectly Specified Arguments in Linux kernel - CVE-2026-98078
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose stale heap data and corrupt connection sequence state.
The vulnerability exists due to incorrect function call argument ordering in the version 1 IPVS synchronization sender when serializing connection sequence data. A remote attacker can send traffic that causes connection sequence data to be synchronized to disclose stale heap data and corrupt connection sequence state.
Only connections with sequence-state flags set are affected.