Buffer Overflow in Linux Kernel's Network Flow Steering Component
CVE-2026-98029

7HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98029?

A vulnerability in the Linux Kernel's network flow steering mechanism allows for potential buffer overflow threats. Specifically, the function nfp_net_get_fs_loc() fails to appropriately respect the buffer size provided by the caller when dumping entries from nn->fs.list into rule_locs[]. This oversight allows an attacker with user privileges to exploit the system by requesting fewer slots than the number of existing flow steering rules, leading to an out-of-bounds read. The issue can be exploited when the buffer's rule count is set to zero, causing a NULL pointer dereference. This vulnerability is addressed by ensuring that the buffer allocation checks are performed adequately, returning an error when the buffer reaches capacity and effectively preventing stale data from being read.

Affected Version(s)

Linux 9eb03bb1c035ff6e2c3a34046419446588253dda < 82812583b9c69c241da6da4186f14e9df2516488

Linux 9eb03bb1c035ff6e2c3a34046419446588253dda

Linux 9eb03bb1c035ff6e2c3a34046419446588253dda

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.