Linux Kernel Vulnerability in PPP Process Management
CVE-2026-98158

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98158?

A vulnerability in the Linux kernel's PPP (Point-to-Point Protocol) processing allows remote attackers to cause a denial of service through an improperly managed headroom in the data frame. The issue arises when an erroneous PPP frame is processed, leading to improper handling of allocated buffer space, which can trigger a kernel panic. This vulnerability exposes systems to crashes when specific faulty frames are sent consecutively, ultimately compromising network stability. The recommended solution involves dropping the problematic frame rather than resetting the headroom, ensuring that subsequent frames utilize properly allocated buffers.

Affected Version(s)

Linux 6722e78c90054101e6797d5944cdc81af9897a0a

Linux 6722e78c90054101e6797d5944cdc81af9897a0a < 0c53eb14975f029abd6b26896a460f0d2aaefe6b

Linux 6722e78c90054101e6797d5944cdc81af9897a0a < 717137221c7d90e7c98bda9a370c9da6cbf015e5

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.