PT-2026-106628 · Linux · Linux
CVE-2026-98299
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
tcp: do not let tcp rmem be set below 4096
We can hit a division by zero crash in tcp rcvbuf grow()
and tcp rcv space adjust():
divide error: 0000 [#1] PREEMPT SMP
RIP: 0010:tcp rcvbuf grow+0x187/0x450 net/ipv4/tcp input.c:939
...
grow = div u64(((u64)rcvwin << 1) * (newval - oldval), oldval);
The division uses oldval = tp->rcvq space.space as divisor.
When tp->rcvq space.space is zero, this leads to a divide-by-zero
exception.
tp->rcvq space.space is initialized in tcp init buffer space():
tp->rcvq space.space = min3(tp->rcv ssthresh, tp->rcv wnd,
(u32)TCP INIT CWND * tp->advmss);
If tcp rmem[1] is configured to very small values (such as 1),
sk->sk rcvbuf is initialized to 1. Then tcp full space(sk), which
computes (sk->sk rcvbuf * scaling ratio) >> 8, truncates to 0.
This sets tp->window clamp = 0, tp->rcv ssthresh = 0, and
tp->rcvq space.space = 0. Later, when data arrives and DRS is invoked,
tcp rcvbuf grow() divides by oldval == 0.
Back in 2015, commit b1cb59cf2efe ("net: sysctl net core: check SNDBUF
and RCVBUF for min length") ensured that net.core.rmem default and
net.core.rmem max cannot be set below SOCK MIN RCVBUF. Similarly,
SO RCVBUF setsockopt enforces max t(int, val * 2, SOCK MIN RCVBUF).
However, net.ipv4.tcp rmem still had .extra1 = SYSCTL ONE, allowing
arbitrarily small values.
Because SOCK MIN RCVBUF depends on sizeof(struct sk buff) and cacheline
alignment, its value varies across architectures and configuration options.
Using a fixed constant of 4096 ensures a predictable, architecture-
independent lower bound that is safely above SOCK MIN RCVBUF everywhere
and matches the documented 4K default.
Fix this by setting tcp rmem.extra1 to 4096 and updating the documentation.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux