CVE-2026-98241

Source
https://cve.org/CVERecord?id=CVE-2026-98241
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98241.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98241
Downstream
Published
2026-10-06T08:45:11Z
Modified
2026-10-07T02:47:29Z
Summary
ipv6: xfrm: use full sockets in local error paths
Details

In the Linux kernel, the following vulnerability has been resolved:

ipv6: xfrm: use full sockets in local error paths

xfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as if it always pointed at a full IPv6 socket.

That is not guaranteed. TCP SYN-ACK skbs can be owned by a TCP_NEW_SYN_RECV request_sock while the output path itself is driven by the full listener. If rerouting selects an IPv6 XFRM tunnel route with a lower MTU, the local PMTU/error handling path can reach these callbacks with that mini-socket still attached to the skb.

The callbacks then miscast the request socket as a full inet/IPv6 socket and can read beyond the request_sock allocation when they access inet_sock or ipv6_pinfo state.

Resolve the owner with skb_to_full_sk() in both callbacks and bail out when no full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error logic, which already reasons about full sockets with skb_to_full_sk().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98241.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
dd767856a36e00b631d65ebc4bb81b19915532d6
Fixed
b1a88633c36d2cbc3831382f3846754d344276fd
Fixed
904a0e827d0d7189271a3a2eb648293809f25efc
Fixed
675919e08ce266b8cac11fd9af29170e762a480f
Fixed
60459c670329d586a58db5d8f811fa5accfe4862
Fixed
ca3d68c3213475b53db6647e159dc73bd1af5ab1
Fixed
4c030a0400ebfd2318361c923a88103b2c67c49f
Fixed
c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8
Fixed
6973a21ee73c5567f883813c8ef414774b45892f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98241.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98241.json"