Out-of-bounds read in Linux kernel - CVE-2026-98375
Published: October 9, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to insufficient validation of the Ethernet header length in xen/netfront handle_incoming_queue() when processing backend-supplied receive packets. A local user can supply a packet whose first receive slot is shorter than ETH_HLEN and is followed by additional slots to cause a denial of service.
Exploitation requires control over the receive slot lengths supplied by the backend.