Numeric Truncation Error in Linux kernel - CVE-2026-98288

 

Numeric Truncation Error in Linux kernel - CVE-2026-98288

Published: October 7, 2026


Vulnerability identifier: #VU153728
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-98288
CWE-ID: CWE-197
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause protocol header lengths to be truncated during TCP segmentation offload.

The vulnerability exists due to numeric truncation in stmmac_tso_xmit() when processing TCP over IPv6 packets with protocol headers longer than 255 bytes. A local user can create a TCP over IPv6 socket with several hundred bytes of sticky destination or hop-by-hop options to cause protocol header lengths to be truncated during TCP segmentation offload.

The packet validation function accepts protocol headers up to 1023 bytes, allowing these packets to reach the affected transmit function.


Affected software

Linux kernel

How to mitigate CVE-2026-98288

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins