CVE-2026-98078

Source
https://cve.org/CVERecord?id=CVE-2026-98078
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98078.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98078
Downstream
Published
2026-09-25T10:24:16Z
Modified
2026-09-26T03:48:32Z
Summary
ipvs: fix reversed sequence option serialization
Details

In the Linux kernel, the following vulnerability has been resolved:

ipvs: fix reversed sequence option serialization

hton_seq() expects the host-order source first and the unaligned network-order destination second. The version 1 sync sender passes these arguments in reverse for both sequence blocks. This leaves 24 bytes of the kmalloc-backed message unwritten. It may disclose stale heap data and replace the live connection sequence state with values read from the buffer.

Pass the connection sequence state as the source and the message payload as the destination for both blocks.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98078.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
986a075795339c5ea1122ce9290dfd5504252eb0
Fixed
e1c9f9446d3eaae323f1689f9e5de3b1ad6e47ec
Fixed
524599714558da83747c04952d378155c69f5b6b
Fixed
de6cc6ec7932bc530f2bb92005dac9123d50659c
Fixed
b04578b74f2d3755548fe9e829e3b2a6c6f966a1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98078.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.39
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98078.json"