PT-2026-106569 · Linux · Linux

CVE-2026-98240

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: ip tunnel: initialize options len before referencing options
The following command triggers a kernel panic:
ip link add d0 type dummy; ip link set d0 up ip route add 10.30.0.0/16 encap ip id 300 geneve opts 4660:66:11223344 dev d0
memcpy: detected buffer overflow: 4 byte write of buffer size 0 kernel BUG at lib/string helpers.c:1044! ... ip tun parse opts.part.0.cold+0x10/0x10 ip tun build state+0x116/0x2a0
On kernels built with GCC 15+ and CONFIG FORTIFY SOURCE, the fortified memcpy() got 0 sized destination with request of 4 bytes length:
static int ip tun parse opts geneve(...) { ... attr = tb[LWTUNNEL IP OPT GENEVE DATA]; data len = nla len(attr); /* == 4 */
struct geneve opt opt = ip tunnel info opts(info) + opts len; memcpy(opt->opt data, nla data(attr), data len); / ^^^^^^^^^^^^^ 0 since options len is assigned afterwards */
Fixed by initializing the counter before the options are referenced. Matching what tunnel key opts set() already does.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98240

Affected Products

Linux