Network Header Vulnerability in Linux Kernel Affects Routing and Forwarding
CVE-2026-98096
What is CVE-2026-98096?
A network header vulnerability in the Linux kernel enables improper handling of IPv6 Segment Routing Headers (SRH), particularly during routing and forwarding processes. The function ipv6_srh_rcv() incorrectly assumes the SRH directly follows the fixed IPv6 header, leading to negative offsets during flow dissection. This mismanagement can cause failures in BPF and C flow dissector logic, and might result in out-of-bounds memory copies or buffer overflows when processed by downstream handlers. To address this, a fix was implemented to correctly adjust skb_network_offset(skb) before routing, enhancing the security and stability of network operations.
Affected Version(s)
Linux 1ababeba4a21f3dba3da3523c670b207fb2feb62
Linux 1ababeba4a21f3dba3da3523c670b207fb2feb62 < 8f44d4160bcdb3136a9145a4b9c7816382976925
Linux 1ababeba4a21f3dba3da3523c670b207fb2feb62 < 9cfbe2c381ab6d00a08e7a5b6028865adfb4e1bc