Linux Kernel Vulnerability in Netfront Affecting Ethernet Packet Handling
CVE-2026-98375

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-98375?

A vulnerability in the Linux kernel's netfront networking driver could lead to improper handling of RX packets due to insufficient validation of Ethernet header lengths. Specifically, the function handle_incoming_queue() fails to adequately check the length of incoming Ethernet frames, which can result in a buffer underflow condition. If the first received slot is less than the required Ethernet header length (ETH_HLEN), it may cause the kernel to access memory beyond the allocated buffer. The proposed solution ensures that received packets are dropped if their lengths are insufficient, thus preventing potential exploitation and maintaining system integrity. This fix improves the overall robustness of network packet processing in the Linux Kernel.

Affected Version(s)

Linux 0d160211965b79de989cf2d170985abeb8da5ec6 < 089e58805c452e52179482b1025a8e309a57f801

Linux 2.6.23

Linux 2.6.23

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.