CVE-2026-98371
Received Received - Intake

xfrm: iptfs runt reassembly panic in Linux kernel

Vulnerability report for CVE-2026-98371, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix runt reassembly panic from short inner tot_len When the start of an inner packet is split across two outer packets such that fewer than 4 bytes land at the end of the first one, __input_process_payload() saves those bytes as a runt and skips the iplen/iphlen validation performed for in-place packets. When the continuation packet arrives, iptfs_reassem_cont() only requires the declared inner length to be >= sizeof(ra_runt) (6) before allocating the reassembly skb with that attacker-controlled length. However, __iptfs_iphlen() always returns the fixed minimum IP header size (20 for IPv4, 40 for IPv6), so for an inner IPv4 tot_len in [6, 19] the header-completion copy writes past the declared packet length, and the subsequent "ipremain -= copylen" underflows to ~4GB, leaving the payload copy length bounded only by blkoff (up to 64KB). At runtime the skb_put() tailroom check turns this into skb_over_panic(), i.e. an unprivileged kernel panic (DoS), reachable locally via userns+netns IPTFS SAs and remotely against IPTFS VPN gateways when the decrypted outer skb is linear (e.g. AF_PACKET taps, tun/tap delivery). Align the runt path with the normal path by requiring the declared inner length to cover at least the IP header size. This also subsumes the previous >= sizeof(ra_runt) check, since the minimum IP header is always larger than the runt buffer. This issue was found by the autokbug dynamic kernel fuzzer at Tencent Yunding Lab.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
Linux Linux 07569476544681816335099929ff3494dfbf6b05
Linux Linux 07569476544681816335099929ff3494dfbf6b05
Linux Linux 07569476544681816335099929ff3494dfbf6b05
Linux Linux 6.14

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability where a flaw in the IPsec Transform (IPTFS) reassembly process can cause a kernel panic. It occurs when an inner packet is split across two outer packets, leading to incorrect length validation. Attackers can exploit this to trigger a denial-of-service (DoS) by causing an unprivileged kernel panic.

Detection Guidance

This vulnerability is specific to the Linux kernel's xfrm iptfs component and may not have direct detection commands. It involves a kernel panic triggered by malformed packets. Monitoring kernel logs for skb_over_panic or similar errors could indicate exploitation attempts. Check if your system uses IPTFS (IP Traffic Flow Security) with 'modprobe -l | grep iptfs' or 'lsmod | grep iptfs'.

Impact Analysis

This vulnerability can cause a system crash (kernel panic) leading to a denial-of-service. It may be triggered locally via user namespaces and network namespaces, or remotely against IPTFS VPN gateways if the decrypted outer packet is linear.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for this vulnerability. Disable IPTFS if not required by removing the module with 'modprobe -r iptfs' or blacklisting it. Restrict access to user namespaces and network namespaces if IPTFS is used. Monitor security advisories for kernel updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98371. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart