PT-2026-106617 · Linux · Linux

CVE-2026-98288

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: stmmac: fix TSO header length truncation
stmmac tso xmit() stores the protocol header length returned by stmmac tso header size() in a u8. stmmac tso valid packet() admits headers up to 1023 bytes, so a header longer than 255 bytes wraps modulo 256 (486 becomes 230, 256 becomes 0).
A TCP over IPv6 socket carrying a few hundred bytes of sticky destination/hop-by-hop options makes skb tcp all headers() exceed 255 while staying below the 1023-byte limit, so such an skb reaches stmmac tso xmit().
Widen proto hdr len to unsigned int, which is sufficient since the value is bounded by the hardware limit, and adjust the debug print specifier accordingly.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98288

Affected Products

Linux