CVE-2026-98299
In the Linux kernel, the following vulnerability has been resolved:
tcp: do not let tcp_rmem be set below 4096
We can hit a division by zero crash in tcp_rcvbuf_grow() and tcp_rcv_space_adjust():
The division uses oldval = tp->rcvq_space.space as divisor. When tp->rcvq_space.space is zero, this leads to a divide-by-zero exception.
If tcp_rmem[1] is configured to very small values (such as 1), sk->sk_rcvbuf is initialized to 1. Then tcp_full_space(sk), which computes (sk->sk_rcvbuf * scaling_ratio) >> 8, truncates to 0. This sets tp->window_clamp = 0, tp->rcv_ssthresh = 0, and tp->rcvq_space.space = 0. Later, when data arrives and DRS is invoked, tcp_rcvbuf_grow() divides by oldval == 0.
Leer descripción completaMostrar menos
Back in 2015, commit b1cb59cf2efe ("net: sysctl_net_core: check SNDBUF and RCVBUF for min length") ensured that net.core.rmem_default and net.core.rmem_max cannot be set below SOCK_MIN_RCVBUF. Similarly, SO_RCVBUF setsockopt enforces max_t(int, val * 2, SOCK_MIN_RCVBUF).
However, net.ipv4.tcp_rmem still had .extra1 = SYSCTL_ONE, allowing arbitrarily small values.
Because SOCK_MIN_RCVBUF depends on sizeof(struct sk_buff) and cacheline alignment, its value varies across architectures and configuration options. Using a fixed constant of 4096 ensures a predictable, architecture- independent lower bound that is safely above SOCK_MIN_RCVBUF everywhere and matches the documented 4K default.
Fix this by setting tcp_rmem.extra1 to 4096 and updating the documentation.
Detalles técnicos trazas, registros y código del informe original
divide error: 0000 [#1] PREEMPT SMP
RIP: 0010:tcp_rcvbuf_grow+0x187/0x450 net/ipv4/tcp_input.c:939
...
grow = div_u64(((u64)rcvwin << 1) * (newval - oldval), oldval);
tp->rcvq_space.space is initialized in tcp_init_buffer_space():
tp->rcvq_space.space = min3(tp->rcv_ssthresh, tp->rcv_wnd,
(u32)TCP_INIT_CWND * tp->advmss);CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1c4bb940c3bb4325bb88ac1b7eaf5faaa39e7d63
- https://git.kernel.org/stable/c/60df201dbb19a1bf6478b56d100f7ae1fe90e46a
- https://git.kernel.org/stable/c/67b83c15bed9eeeb8d1a6dbf88a5f79525970173
- https://git.kernel.org/stable/c/7898bda1ebc198f5559b301a96dd5398edd4d4d3
- https://git.kernel.org/stable/c/83a945a529d6e002dd7339c532288a931f463dba
- https://git.kernel.org/stable/c/879907631b9e70eedb62d76461b29afa106ebe7a
- https://git.kernel.org/stable/c/8e32532d0fa3191ecf9524b0e6bafa0832e712ba
- https://git.kernel.org/stable/c/9a4f49bf8d2da4e52e904f60c29cca317bab9b3a
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98299",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "879907631b9e70eedb62d76461b29afa106ebe7a",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "8e32532d0fa3191ecf9524b0e6bafa0832e712ba",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "67b83c15bed9eeeb8d1a6dbf88a5f79525970173",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "9a4f49bf8d2da4e52e904f60c29cca317bab9b3a",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "60df201dbb19a1bf6478b56d100f7ae1fe90e46a",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "7898bda1ebc198f5559b301a96dd5398edd4d4d3",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "1c4bb940c3bb4325bb88ac1b7eaf5faaa39e7d63",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "83a945a529d6e002dd7339c532288a931f463dba",
"versionType": "git"
}
],
"programFiles": [
"Documentation/networking/ip-sysctl.rst",
"net/ipv4/sysctl_net_ipv4.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.12",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"Documentation/networking/ip-sysctl.rst",
"net/ipv4/sysctl_net_ipv4.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:20.697",
"references": [
{
"url": "https://git.kernel.org/stable/c/1c4bb940c3bb4325bb88ac1b7eaf5faaa39e7d63",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/60df201dbb19a1bf6478b56d100f7ae1fe90e46a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/67b83c15bed9eeeb8d1a6dbf88a5f79525970173",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7898bda1ebc198f5559b301a96dd5398edd4d4d3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/83a945a529d6e002dd7339c532288a931f463dba",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/879907631b9e70eedb62d76461b29afa106ebe7a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8e32532d0fa3191ecf9524b0e6bafa0832e712ba",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9a4f49bf8d2da4e52e904f60c29cca317bab9b3a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: do not let tcp_rmem be set below 4096\n\nWe can hit a division by zero crash in tcp_rcvbuf_grow()\nand tcp_rcv_space_adjust():\n\ndivide error: 0000 [#1] PREEMPT SMP\nRIP: 0010:tcp_rcvbuf_grow+0x187/0x450 net/ipv4/tcp_input.c:939\n...\ngrow = div_u64(((u64)rcvwin << 1) * (newval - oldval), oldval);\n\nThe division uses oldval = tp->rcvq_space.space as divisor.\nWhen tp->rcvq_space.space is zero, this leads to a divide-by-zero\nexception.\n\ntp->rcvq_space.space is initialized in tcp_init_buffer_space():\n tp->rcvq_space.space = min3(tp->rcv_ssthresh, tp->rcv_wnd,\n (u32)TCP_INIT_CWND * tp->advmss);\n\nIf tcp_rmem[1] is configured to very small values (such as 1),\nsk->sk_rcvbuf is initialized to 1. Then tcp_full_space(sk), which\ncomputes (sk->sk_rcvbuf * scaling_ratio) >> 8, truncates to 0.\nThis sets tp->window_clamp = 0, tp->rcv_ssthresh = 0, and\ntp->rcvq_space.space = 0. Later, when data arrives and DRS is invoked,\ntcp_rcvbuf_grow() divides by oldval == 0.\n\nBack in 2015, commit b1cb59cf2efe (\"net: sysctl_net_core: check SNDBUF\nand RCVBUF for min length\") ensured that net.core.rmem_default and\nnet.core.rmem_max cannot be set below SOCK_MIN_RCVBUF. Similarly,\nSO_RCVBUF setsockopt enforces max_t(int, val * 2, SOCK_MIN_RCVBUF).\n\nHowever, net.ipv4.tcp_rmem still had .extra1 = SYSCTL_ONE, allowing\narbitrarily small values.\n\nBecause SOCK_MIN_RCVBUF depends on sizeof(struct sk_buff) and cacheline\nalignment, its value varies across architectures and configuration options.\nUsing a fixed constant of 4096 ensures a predictable, architecture-\nindependent lower bound that is safely above SOCK_MIN_RCVBUF everywhere\nand matches the documented 4K default.\n\nFix this by setting tcp_rmem.extra1 to 4096 and updating the documentation."
}
],
"lastModified": "2026-10-06T09:18:20.697",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}