CVE-2026-98251
Received Received - Intake

Memory Corruption in Open vSwitch Kernel Module

Vulnerability report for CVE-2026-98251, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: openvswitch: avoid reallocating confirmed conntrack labels ovs_ct_get_conn_labels() adds the labels extension when a conntrack entry does not have one. Confirmed conntracks can be read locklessly, so adding an extension may reallocate and free the extension block while another CPU accesses it. Only add the extension for unconfirmed conntracks. A confirmed conntrack without labels now fails the caller's label operation instead of reallocating its extension storage.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux c2ac667358708d7cce64c78f58af6adf4c1e848b
Linux Linux c2ac667358708d7cce64c78f58af6adf4c1e848b
Linux Linux c2ac667358708d7cce64c78f58af6adf4c1e848b
Linux Linux c2ac667358708d7cce64c78f58af6adf4c1e848b
Linux Linux c2ac667358708d7cce64c78f58af6adf4c1e848b
Linux Linux c2ac667358708d7cce64c78f58af6adf4c1e848b
Linux Linux c2ac667358708d7cce64c78f58af6adf4c1e848b
Linux Linux c2ac667358708d7cce64c78f58af6adf4c1e848b
Linux Linux 4.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a race condition in Open vSwitch's connection tracking label handling. The issue occurs when ovs_ct_get_conn_labels() attempts to add a labels extension to a conntrack entry that lacks one. For confirmed conntracks, which can be accessed without locking, this operation may trigger reallocation and freeing of the extension block while another CPU is still using it, leading to potential memory corruption or crashes.

Detection Guidance

This vulnerability is specific to the Linux kernel's Open vSwitch (OVS) module and involves conntrack label handling. Detection requires checking the OVS and kernel versions for the affected code paths. Use commands like 'uname -a' to check kernel version and 'ovs-vsctl --version' for OVS version. Look for kernel logs or OVS errors related to conntrack label reallocation.

Impact Analysis

This vulnerability could cause system instability, crashes, or unexpected behavior in systems running Open vSwitch with connection tracking enabled. It may lead to denial-of-service conditions or data corruption if exploited, particularly in network environments relying on Open vSwitch for virtual networking.

Mitigation Strategies

Apply the latest kernel and Open vSwitch updates to patch the vulnerability. If immediate patching is not possible, consider disabling OVS conntrack label operations as a temporary workaround. Monitor system logs for conntrack-related errors and restrict network access to reduce exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98251. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart