Incorrect calculation in Linux kernel - CVE-2026-97618
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause incorrect consumption of provided buffer-ring space.
The vulnerability exists due to improper buffer consumption accounting in io_uring recv and recvmsg operations when processing an incoming packet larger than the provided buffer with MSG_TRUNC. A remote attacker can send an oversized packet to cause incorrect consumption of provided buffer-ring space.
Multishot receives already limit consumption according to the available payload size.