PT-2026-106570 · Linux · Linux

CVE-2026-98241

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ipv6: xfrm: use full sockets in local error paths
xfrm6 local rxpmtu() and xfrm6 local error() dereference skb->sk as if it always pointed at a full IPv6 socket.
That is not guaranteed. TCP SYN-ACK skbs can be owned by a TCP NEW SYN RECV request sock while the output path itself is driven by the full listener. If rerouting selects an IPv6 XFRM tunnel route with a lower MTU, the local PMTU/error handling path can reach these callbacks with that mini-socket still attached to the skb.
The callbacks then miscast the request socket as a full inet/IPv6 socket and can read beyond the request sock allocation when they access inet sock or ipv6 pinfo state.
Resolve the owner with skb to full sk() in both callbacks and bail out when no full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error logic, which already reasons about full sockets with skb to full sk().
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98241

Affected Products

Linux