CVE-2026-98288

Source
https://cve.org/CVERecord?id=CVE-2026-98288
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98288.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98288
Downstream
Published
2026-10-06T08:45:48Z
Modified
2026-10-08T02:52:56Z
Summary
net: stmmac: fix TSO header length truncation
Details

In the Linux kernel, the following vulnerability has been resolved:

net: stmmac: fix TSO header length truncation

stmmac_tso_xmit() stores the protocol header length returned by stmmac_tso_header_size() in a u8. stmmac_tso_valid_packet() admits headers up to 1023 bytes, so a header longer than 255 bytes wraps modulo 256 (486 becomes 230, 256 becomes 0).

A TCP over IPv6 socket carrying a few hundred bytes of sticky destination/hop-by-hop options makes skb_tcp_all_headers() exceed 255 while staying below the 1023-byte limit, so such an skb reaches stmmac_tso_xmit().

Widen proto_hdr_len to unsigned int, which is sufficient since the value is bounded by the hardware limit, and adjust the debug print specifier accordingly.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98288.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9edfa7dab8112a012b349b7937f5444fdc21e8f9
Fixed
bcf6013c2b4d732c6e4bf4d0f6ae4a18d63d414b
Fixed
15989abd74f16f44bf953d056b95f1d2fda9b0cd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98288.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.13.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98288.json"