Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-98021
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause excessive memory allocation.
The vulnerability exists due to improper validation of a specified quantity in input in the IFLA_TXQLEN netlink attribute when processing netlink requests that specify a transmit queue length. A local user can submit a netlink request with an oversized tx_queue_len value to cause excessive memory allocation.
Exploitation requires network scheduling, veth, user namespace, and network namespace support.