PT-2026-106628 · Linux · Linux

CVE-2026-98299

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
tcp: do not let tcp rmem be set below 4096
We can hit a division by zero crash in tcp rcvbuf grow() and tcp rcv space adjust():
divide error: 0000 [#1] PREEMPT SMP RIP: 0010:tcp rcvbuf grow+0x187/0x450 net/ipv4/tcp input.c:939 ... grow = div u64(((u64)rcvwin << 1) * (newval - oldval), oldval);
The division uses oldval = tp->rcvq space.space as divisor. When tp->rcvq space.space is zero, this leads to a divide-by-zero exception.
tp->rcvq space.space is initialized in tcp init buffer space(): tp->rcvq space.space = min3(tp->rcv ssthresh, tp->rcv wnd, (u32)TCP INIT CWND * tp->advmss);
If tcp rmem[1] is configured to very small values (such as 1), sk->sk rcvbuf is initialized to 1. Then tcp full space(sk), which computes (sk->sk rcvbuf * scaling ratio) >> 8, truncates to 0. This sets tp->window clamp = 0, tp->rcv ssthresh = 0, and tp->rcvq space.space = 0. Later, when data arrives and DRS is invoked, tcp rcvbuf grow() divides by oldval == 0.
Back in 2015, commit b1cb59cf2efe ("net: sysctl net core: check SNDBUF and RCVBUF for min length") ensured that net.core.rmem default and net.core.rmem max cannot be set below SOCK MIN RCVBUF. Similarly, SO RCVBUF setsockopt enforces max t(int, val * 2, SOCK MIN RCVBUF).
However, net.ipv4.tcp rmem still had .extra1 = SYSCTL ONE, allowing arbitrarily small values.
Because SOCK MIN RCVBUF depends on sizeof(struct sk buff) and cacheline alignment, its value varies across architectures and configuration options. Using a fixed constant of 4096 ensures a predictable, architecture- independent lower bound that is safely above SOCK MIN RCVBUF everywhere and matches the documented 4K default.
Fix this by setting tcp rmem.extra1 to 4096 and updating the documentation.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98299

Affected Products

Linux