CVE-2026-98233
Received
Received - Intake
Packet Socket RX Owner Clear on VNET Header Error
Vulnerability report for CVE-2026-98233, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
net/packet: clear RX owner on VNET header error
Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race
condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2
ring slot before converting the virtio-net header. If the conversion
fails, the drop path leaves the slot claimed.
With a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves
the only slot unavailable, so the ring also drops the next valid packet.
Clear the ownership bit on this error path. TPACKET_V3 already clears
its block state here.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 |
| Linux | Linux | 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 |
| Linux | Linux | 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 |
| Linux | Linux | 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 |
| Linux | Linux | 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 |
| Linux | Linux | 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 |
| Linux | Linux | 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 |
| Linux | Linux | 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 |
| Linux | Linux | 2975472e042e0bbfeeabddc5023cb8c011ec5a07 |
| Linux | Linux | 6fb0e4385928900ccb8697748555b3f54bba5193 |
| Linux | Linux | 86137342fd4cf52882842aa8d1318b2661f08e8a |
| Linux | Linux | b06e4d3ed4044c2facf10a511d809f9aa29d960e |
| Linux | Linux | 4.14.175 |
| Linux | Linux | 4.19.114 |
| Linux | Linux | 5.4.29 |
| Linux | Linux | 5.5.14 |
| Linux | Linux | 5.6 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |