Out-of-Bounds Memory Read in Linux Kernel's IPTFS Functionality
CVE-2026-98372
What is CVE-2026-98372?
A critical issue has been identified in the Linux kernel's IPTFS functionality, specifically within the iptfs_skb_reset_frag_walk() routine. This function fails to adequately check the boundaries of fragment offsets, which can lead to an out-of-bounds read of memory. When a crafted IP-TFS (AGGFRAG) payload is processed, it may cause the walk to exceed valid fragment limits, ultimately reading from invalid memory addresses. The vulnerability can be triggered during the packet reception process, leading to potential system instability and exploitation risks. Proper boundary checks need to be implemented to mitigate this issue effectively.
Affected Version(s)
Linux 5f2b6a9095743a6bf1f34c43c4fe78fa8bdf5ad7 < 7e1c6884a0b494b7e3f204877f94c1e07a117bf7
Linux 5f2b6a9095743a6bf1f34c43c4fe78fa8bdf5ad7
Linux 5f2b6a9095743a6bf1f34c43c4fe78fa8bdf5ad7