PT-2026-98694 · Linux · Linux
CVE-2026-98031
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
nexthop: Initialize extack in remove nh grp entry()
remove nh grp entry() prints the extack message when a listener fails
to replace the reduced nexthop group. However, extack is not
initialized and listeners are not required to set a message when
returning an error. Neither netdevsim nor mlxsw do so when an
allocation fails, resulting in the dereference of an uninitialized
stack pointer.
Fix by zero-initializing extack, as was done in commit 6347c5314cee
("nexthop: initialize extack in nh res bucket migrate()").
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux