PT-2026-98759 · Linux · Linux Kernel

CVE-2026-98096

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description An issue exists in the ipv6 srh rcv() function where the network header is not correctly restored before routing and forwarding. When segments left is greater than 0, the function incorrectly assumes the Segment Routing Header (SRH) immediately follows the IPv6 header. If another extension header, such as a Hop-by-Hop options header, precedes the SRH, the skb network offset() remains negative. This results in two primary issues: it breaks BPF and C flow dissector logic during ip6 route input() via fib6 rules early flow dissect() and skb flow dissect(), and it can trigger out-of-bounds memcpy or buffer overflows in downstream handlers like sch fragment() or neighbour output when the negative offset is treated as an unsigned length during forwarding via ip6 forward() or redirection via act mirred.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98096

Affected Products

Linux Kernel