PT-2026-98752 · Linux · Linux
CVE-2026-98089
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bonding: alb: fix uninitialized transport header access in alb determine nd()
alb determine nd() uses icmp6 hdr(skb) to inspect ICMPv6 headers.
However, in xmit paths (e.g. packets sent via AF PACKET / raw sockets
or forwarded packets), skb->transport header is not guaranteed to be
initialized. While pskb network may pull() ensures the packet data is
linear starting from the network header, it does not set or adjust the
transport header offset.
Dereferencing icmp6 hdr(skb) can therefore access out-of-bounds memory.
Fetch the icmp6hdr directly after ipv6hdr following pskb network may pull(),
and reload ipv6hdr in case pskb may pull() reallocated skb->head.
Also remove the unused bond argument from alb determine nd().
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux