Numeric Truncation Error in Linux kernel - CVE-2026-98288
Published: October 7, 2026
Vulnerability details
The vulnerability allows a local user to cause protocol header lengths to be truncated during TCP segmentation offload.
The vulnerability exists due to numeric truncation in stmmac_tso_xmit() when processing TCP over IPv6 packets with protocol headers longer than 255 bytes. A local user can create a TCP over IPv6 socket with several hundred bytes of sticky destination or hop-by-hop options to cause protocol header lengths to be truncated during TCP segmentation offload.
The packet validation function accepts protocol headers up to 1023 bytes, allowing these packets to reach the affected transmit function.