← All Advisories

CVE-2026-98096

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98096

Key Details

CVECVE-2026-98096
CVSS Score / Version7.4 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ipv6: sr: restore network header before routing and forwarding

ipv6_srh_rcv() runs with skb->data at the Segment Routing Header (SRH)

while skb_network_header() points at the IPv6 header.

When segments_left > 0, ipv6_srh_rcv() previously restored the skb->data

position by pushing sizeof(struct ipv6hdr), assuming the SRH immediately

followed the fixed IPv6 header. If another extension header (such as a

Hop-by-Hop options header) precedes the SRH, skb_network_offset()

remained negative.

This led to two problems:

1. During ip6_route_input(), fib6_rules_early_flow_dissect() invokes

__skb_flow_dissect() which passes the negative skb_network_offset()

to flow dissection, breaking BPF and C flow dissector logic.

2. If forwarded via ip6_forward() or redirected via act_mirred, downstream

handlers (like sch_fragment() or neighbour output) pass the negative

offset as an unsigned length, triggering OOB memcpy or buffer overflows.

Fix this by pushing -skb_network_offset(skb) before routing, ensuring

skb_network_offset(skb) is 0 for route lookup / flow dissection as well as

downstream forwarding. On the loopback path, pull skb_transport_offset(skb)

to restore skb->data to the SRH before looping back. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98096
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98096