PT-2026-106562 · Linux · Linux

CVE-2026-98233

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net/packet: clear RX owner on VNET header error
Commit 61fad6816fc1 ("net/packet: tpacket rcv: avoid a producer race condition") added rx owner map and made tpacket rcv() claim a V1 or V2 ring slot before converting the virtio-net header. If the conversion fails, the drop path leaves the slot claimed.
With a one-frame TPACKET V2 ring, an unsupported UDP GSO packet leaves the only slot unavailable, so the ring also drops the next valid packet.
Clear the ownership bit on this error path. TPACKET V3 already clears its block state here.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98233

Affected Products

Linux