Denial of Service in Linux Kernel Affecting IP Tunneling Functions
CVE-2026-98371

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98371?

A vulnerability has been identified in the Linux kernel related to the IP tunneling functionalities, specifically affecting the handling of inner packets that are split across outer packets. When the initial segment of an inner packet does not align correctly, the kernel mishandles the length checks, which can lead to significant issues including crashes or Denial of Service due to improper memory access. This flaw can be exploited both locally in user namespaces and remotely against VPN gateways, compromising system stability. To mitigate this risk, it is essential to ensure that the declared inner packet length appropriately accounts for the minimum IP header size, preventing potential security breaches.

Affected Version(s)

Linux 07569476544681816335099929ff3494dfbf6b05

Linux 07569476544681816335099929ff3494dfbf6b05 < 5b8afb56ccb7c014b0f1ac40341708b200443c2d

Linux 07569476544681816335099929ff3494dfbf6b05

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.