CVE-2026-98251

Source
https://cve.org/CVERecord?id=CVE-2026-98251
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98251.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98251
Downstream
Published
2026-10-06T08:45:18Z
Modified
2026-10-07T02:47:30Z
Summary
openvswitch: avoid reallocating confirmed conntrack labels
Details

In the Linux kernel, the following vulnerability has been resolved:

openvswitch: avoid reallocating confirmed conntrack labels

ovs_ct_get_conn_labels() adds the labels extension when a conntrack entry does not have one. Confirmed conntracks can be read locklessly, so adding an extension may reallocate and free the extension block while another CPU accesses it.

Only add the extension for unconfirmed conntracks. A confirmed conntrack without labels now fails the caller's label operation instead of reallocating its extension storage.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98251.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c2ac667358708d7cce64c78f58af6adf4c1e848b
Fixed
4371d79ea74407fb992c985b1f94391e35bb8289
Fixed
7ff688aceada1160331a789385ea146f62fbddf7
Fixed
05eab8dced6bf4d3009a6eeee16ddac99047dc83
Fixed
579d87ec1e1e85729a6cb2c25961e58beb78640c
Fixed
2e6dd889c325abf23821e1459c3ffef59b7f0009
Fixed
d16f089bd700f45d720ce989d5495e1dc3be0cf8
Fixed
8c9fcc6c33950d3db551af664d1fd3d998bfee56
Fixed
3f118c8217c109fd13ca61caa301d72c483897ef

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98251.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98251.json"