Network Header Vulnerability in Linux Kernel Affects Routing and Forwarding
CVE-2026-98096

7.4HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98096?

A network header vulnerability in the Linux kernel enables improper handling of IPv6 Segment Routing Headers (SRH), particularly during routing and forwarding processes. The function ipv6_srh_rcv() incorrectly assumes the SRH directly follows the fixed IPv6 header, leading to negative offsets during flow dissection. This mismanagement can cause failures in BPF and C flow dissector logic, and might result in out-of-bounds memory copies or buffer overflows when processed by downstream handlers. To address this, a fix was implemented to correctly adjust skb_network_offset(skb) before routing, enhancing the security and stability of network operations.

Affected Version(s)

Linux 1ababeba4a21f3dba3da3523c670b207fb2feb62

Linux 1ababeba4a21f3dba3da3523c670b207fb2feb62 < 8f44d4160bcdb3136a9145a4b9c7816382976925

Linux 1ababeba4a21f3dba3da3523c670b207fb2feb62 < 9cfbe2c381ab6d00a08e7a5b6028865adfb4e1bc

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.