PT-2026-98760 · Linux · Linux

CVE-2026-98097

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
tipc: Dont send random pad bytes in RESET/ACTIVATE messages
The interface name is passed in a fixed length (TIPC MAX IF NAME) buffer. Replace the strcpy(data, l->if name) with memcpy() so that the pad bytes are actually written (l->if name[] is zero padded) rather than sending random bytes from the skb to the remote system.
Replace two other strcpy() with strscpy().
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98097

Affected Products

Linux