« Volver al listado

CVE-2026-98299

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

tcp: do not let tcp_rmem be set below 4096

We can hit a division by zero crash in tcp_rcvbuf_grow() and tcp_rcv_space_adjust():

The division uses oldval = tp->rcvq_space.space as divisor. When tp->rcvq_space.space is zero, this leads to a divide-by-zero exception.

If tcp_rmem[1] is configured to very small values (such as 1), sk->sk_rcvbuf is initialized to 1. Then tcp_full_space(sk), which computes (sk->sk_rcvbuf * scaling_ratio) >> 8, truncates to 0. This sets tp->window_clamp = 0, tp->rcv_ssthresh = 0, and tp->rcvq_space.space = 0. Later, when data arrives and DRS is invoked, tcp_rcvbuf_grow() divides by oldval == 0.

Leer descripción completaMostrar menos

Back in 2015, commit b1cb59cf2efe ("net: sysctl_net_core: check SNDBUF and RCVBUF for min length") ensured that net.core.rmem_default and net.core.rmem_max cannot be set below SOCK_MIN_RCVBUF. Similarly, SO_RCVBUF setsockopt enforces max_t(int, val * 2, SOCK_MIN_RCVBUF).

However, net.ipv4.tcp_rmem still had .extra1 = SYSCTL_ONE, allowing arbitrarily small values.

Because SOCK_MIN_RCVBUF depends on sizeof(struct sk_buff) and cacheline alignment, its value varies across architectures and configuration options. Using a fixed constant of 4096 ensures a predictable, architecture- independent lower bound that is safely above SOCK_MIN_RCVBUF everywhere and matches the documented 4K default.

Fix this by setting tcp_rmem.extra1 to 4096 and updating the documentation.

Detalles técnicos trazas, registros y código del informe original
divide error: 0000 [#1] PREEMPT SMP
RIP: 0010:tcp_rcvbuf_grow+0x187/0x450 net/ipv4/tcp_input.c:939
...
grow = div_u64(((u64)rcvwin << 1) * (newval - oldval), oldval);

tp->rcvq_space.space is initialized in tcp_init_buffer_space():
    tp->rcvq_space.space = min3(tp->rcv_ssthresh, tp->rcv_wnd,
                                (u32)TCP_INIT_CWND * tp->advmss);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98299",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "879907631b9e70eedb62d76461b29afa106ebe7a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "8e32532d0fa3191ecf9524b0e6bafa0832e712ba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "67b83c15bed9eeeb8d1a6dbf88a5f79525970173",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "9a4f49bf8d2da4e52e904f60c29cca317bab9b3a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "60df201dbb19a1bf6478b56d100f7ae1fe90e46a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "7898bda1ebc198f5559b301a96dd5398edd4d4d3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "1c4bb940c3bb4325bb88ac1b7eaf5faaa39e7d63",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "83a945a529d6e002dd7339c532288a931f463dba",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "Documentation/networking/ip-sysctl.rst",
            "net/ipv4/sysctl_net_ipv4.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "Documentation/networking/ip-sysctl.rst",
            "net/ipv4/sysctl_net_ipv4.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:20.697",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1c4bb940c3bb4325bb88ac1b7eaf5faaa39e7d63",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/60df201dbb19a1bf6478b56d100f7ae1fe90e46a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/67b83c15bed9eeeb8d1a6dbf88a5f79525970173",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7898bda1ebc198f5559b301a96dd5398edd4d4d3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/83a945a529d6e002dd7339c532288a931f463dba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/879907631b9e70eedb62d76461b29afa106ebe7a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8e32532d0fa3191ecf9524b0e6bafa0832e712ba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9a4f49bf8d2da4e52e904f60c29cca317bab9b3a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: do not let tcp_rmem be set below 4096\n\nWe can hit a division by zero crash in tcp_rcvbuf_grow()\nand tcp_rcv_space_adjust():\n\ndivide error: 0000 [#1] PREEMPT SMP\nRIP: 0010:tcp_rcvbuf_grow+0x187/0x450 net/ipv4/tcp_input.c:939\n...\ngrow = div_u64(((u64)rcvwin << 1) * (newval - oldval), oldval);\n\nThe division uses oldval = tp->rcvq_space.space as divisor.\nWhen tp->rcvq_space.space is zero, this leads to a divide-by-zero\nexception.\n\ntp->rcvq_space.space is initialized in tcp_init_buffer_space():\n    tp->rcvq_space.space = min3(tp->rcv_ssthresh, tp->rcv_wnd,\n                                (u32)TCP_INIT_CWND * tp->advmss);\n\nIf tcp_rmem[1] is configured to very small values (such as 1),\nsk->sk_rcvbuf is initialized to 1. Then tcp_full_space(sk), which\ncomputes (sk->sk_rcvbuf * scaling_ratio) >> 8, truncates to 0.\nThis sets tp->window_clamp = 0, tp->rcv_ssthresh = 0, and\ntp->rcvq_space.space = 0. Later, when data arrives and DRS is invoked,\ntcp_rcvbuf_grow() divides by oldval == 0.\n\nBack in 2015, commit b1cb59cf2efe (\"net: sysctl_net_core: check SNDBUF\nand RCVBUF for min length\") ensured that net.core.rmem_default and\nnet.core.rmem_max cannot be set below SOCK_MIN_RCVBUF. Similarly,\nSO_RCVBUF setsockopt enforces max_t(int, val * 2, SOCK_MIN_RCVBUF).\n\nHowever, net.ipv4.tcp_rmem still had .extra1 = SYSCTL_ONE, allowing\narbitrarily small values.\n\nBecause SOCK_MIN_RCVBUF depends on sizeof(struct sk_buff) and cacheline\nalignment, its value varies across architectures and configuration options.\nUsing a fixed constant of 4096 ensures a predictable, architecture-\nindependent lower bound that is safely above SOCK_MIN_RCVBUF everywhere\nand matches the documented 4K default.\n\nFix this by setting tcp_rmem.extra1 to 4096 and updating the documentation."
    }
  ],
  "lastModified": "2026-10-06T09:18:20.697",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}