« Volver al listado

CVE-2026-98240

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net: ip_tunnel: initialize `options_len` before referencing options

The following command triggers a kernel panic:

On kernels built with GCC 15+ and `CONFIG_FORTIFY_SOURCE`, the fortified `memcpy()` got 0 sized destination with request of 4 bytes length:

Fixed by initializing the counter before the options are referenced. Matching what `tunnel_key_opts_set()` already does.

Detalles técnicos trazas, registros y código del informe original
  ip link add d0 type dummy; ip link set d0 up
  ip route add 10.30.0.0/16 \
    encap ip id 300 geneve_opts 4660:66:11223344 dev d0

  memcpy: detected buffer overflow: 4 byte write of buffer size 0
  kernel BUG at lib/string_helpers.c:1044!
  ...
  ip_tun_parse_opts.part.0.cold+0x10/0x10
  ip_tun_build_state+0x116/0x2a0

  static int ip_tun_parse_opts_geneve(...)
  {
      ...
      attr = tb[LWTUNNEL_IP_OPT_GENEVE_DATA];
      data_len = nla_len(attr); /* == 4 */

      struct geneve_opt *opt = ip_tunnel_info_opts(info) + opts_len;
      memcpy(opt->opt_data, nla_data(attr), data_len);
      /*     ^^^^^^^^^^^^^ 0 since options_len is assigned afterwards */

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98240",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "bb5e62f2d547c4de6d1b144cbce2373a76c33f18",
              "lessThan": "9907325257b4b382f26aafd5d9a8d47915907dd5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bb5e62f2d547c4de6d1b144cbce2373a76c33f18",
              "lessThan": "0f6a6beb01c068fcd5274eabf22c260039749fea",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bb5e62f2d547c4de6d1b144cbce2373a76c33f18",
              "lessThan": "455ebeadf714f51e1dbbd6a022c74c9215b1cd76",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/ipv4/ip_tunnel_core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/ipv4/ip_tunnel_core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:11.960",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0f6a6beb01c068fcd5274eabf22c260039749fea",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/455ebeadf714f51e1dbbd6a022c74c9215b1cd76",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9907325257b4b382f26aafd5d9a8d47915907dd5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip_tunnel: initialize `options_len` before referencing options\n\nThe following command triggers a kernel panic:\n\n  ip link add d0 type dummy; ip link set d0 up\n  ip route add 10.30.0.0/16 \\\n    encap ip id 300 geneve_opts 4660:66:11223344 dev d0\n\n  memcpy: detected buffer overflow: 4 byte write of buffer size 0\n  kernel BUG at lib/string_helpers.c:1044!\n  ...\n  ip_tun_parse_opts.part.0.cold+0x10/0x10\n  ip_tun_build_state+0x116/0x2a0\n\nOn kernels built with GCC 15+ and `CONFIG_FORTIFY_SOURCE`, the fortified\n`memcpy()` got 0 sized destination with request of 4 bytes length:\n\n  static int ip_tun_parse_opts_geneve(...)\n  {\n      ...\n      attr = tb[LWTUNNEL_IP_OPT_GENEVE_DATA];\n      data_len = nla_len(attr); /* == 4 */\n\n      struct geneve_opt *opt = ip_tunnel_info_opts(info) + opts_len;\n      memcpy(opt->opt_data, nla_data(attr), data_len);\n      /*     ^^^^^^^^^^^^^ 0 since options_len is assigned afterwards */\n\nFixed by initializing the counter before the options are referenced.\nMatching what `tunnel_key_opts_set()` already does."
    }
  ],
  "lastModified": "2026-10-06T09:18:11.960",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}