{"id":"CVE-2026-98240","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip_tunnel: initialize `options_len` before referencing options\n\nThe following command triggers a kernel panic:\n\n  ip link add d0 type dummy; ip link set d0 up\n  ip…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip_tunnel: initialize `options_len` before referencing options\n\nThe following command triggers a kernel panic:\n\n  ip link add d0 type dummy; ip link set d0 up\n  ip…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= bb5e62f2d547c4de6d1b144cbce2373a76c33f18 < 9907325257b4b382f26aafd5d9a8d47915907dd5","Linux >= bb5e62f2d547c4de6d1b144cbce2373a76c33f18 < 0f6a6beb01c068fcd5274eabf22c260039749fea","Linux >= bb5e62f2d547c4de6d1b144cbce2373a76c33f18 < 455ebeadf714f51e1dbbd6a022c74c9215b1cd76","Linux 6.15"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:11.960","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98240","references":[{"url":"https://git.kernel.org/stable/c/0f6a6beb01c068fcd5274eabf22c260039749fea","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/455ebeadf714f51e1dbbd6a022c74c9215b1cd76","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9907325257b4b382f26aafd5d9a8d47915907dd5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.434Z","slug":"CVE-2026-98240","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip_tunnel: initialize `options_len` before referencing options\n\nThe following command triggers a kernel panic:\n\n  ip link add d0 type dummy; ip link set d0 up\n  ip route add 10.30.0.0/16 \\\n    encap ip id 300 geneve_opts 4660:66:11223344 dev d0\n\n  memcpy: detected buffer overflow: 4 byte write of buffer size 0\n  kernel BUG at lib/string_helpers.c:1044!\n  ...\n  ip_tun_parse_opts.part.0.cold+0x10/0x10\n  ip_tun_build_state+0x116/0x2a0\n\nOn kernels built with GCC 15+ and `CONFIG_FORTIFY_SOURCE`, the fortified\n`memcpy()` got 0 sized destination with request of 4 bytes length:\n\n  static int ip_tun_parse_opts_geneve(...)\n  {\n      ...\n      attr = tb[LWTUNNEL_IP_OPT_GENEVE_DATA];\n      data_len = nla_len(attr); /* == 4 */\n\n      struct geneve_opt *opt = ip_tunnel_info_opts(info) + opts_len;\n      memcpy(opt->opt_data, nla_data(attr), data_len);\n      /*     ^^^^^^^^^^^^^ 0 since options_len is assigned afterwards */\n\nFixed by initializing the counter before the options are referenced.\nMatching what `tunnel_key_opts_set()` already does.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}