PT-2026-106569 · Linux · Linux
CVE-2026-98240
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: ip tunnel: initialize
options len before referencing optionsThe following command triggers a kernel panic:
ip link add d0 type dummy; ip link set d0 up
ip route add 10.30.0.0/16
encap ip id 300 geneve opts 4660:66:11223344 dev d0
memcpy: detected buffer overflow: 4 byte write of buffer size 0
kernel BUG at lib/string helpers.c:1044!
...
ip tun parse opts.part.0.cold+0x10/0x10
ip tun build state+0x116/0x2a0
On kernels built with GCC 15+ and
CONFIG FORTIFY SOURCE, the fortified
memcpy() got 0 sized destination with request of 4 bytes length:static int ip tun parse opts geneve(...)
{
...
attr = tb[LWTUNNEL IP OPT GENEVE DATA];
data len = nla len(attr); /* == 4 */
struct geneve opt opt = ip tunnel info opts(info) + opts len;
memcpy(opt->opt data, nla data(attr), data len);
/ ^^^^^^^^^^^^^ 0 since options len is assigned afterwards */
Fixed by initializing the counter before the options are referenced.
Matching what
tunnel key opts set() already does. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux