{"id":"CVE-2026-98241","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: xfrm: use full sockets in local error paths\n\nxfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as if it\nalways pointed at a full IPv6 socket.\n\nThat…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: xfrm: use full sockets in local error paths\n\nxfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as if it\nalways pointed at a full IPv6 socket.\n\nThat…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= dd767856a36e00b631d65ebc4bb81b19915532d6 < b1a88633c36d2cbc3831382f3846754d344276fd","Linux >= dd767856a36e00b631d65ebc4bb81b19915532d6 < 904a0e827d0d7189271a3a2eb648293809f25efc","Linux >= dd767856a36e00b631d65ebc4bb81b19915532d6 < 675919e08ce266b8cac11fd9af29170e762a480f","Linux >= dd767856a36e00b631d65ebc4bb81b19915532d6 < 60459c670329d586a58db5d8f811fa5accfe4862","Linux >= dd767856a36e00b631d65ebc4bb81b19915532d6 < ca3d68c3213475b53db6647e159dc73bd1af5ab1","Linux >= dd767856a36e00b631d65ebc4bb81b19915532d6 < 4c030a0400ebfd2318361c923a88103b2c67c49f","Linux >= dd767856a36e00b631d65ebc4bb81b19915532d6 < c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8","Linux >= dd767856a36e00b631d65ebc4bb81b19915532d6 < 6973a21ee73c5567f883813c8ef414774b45892f","Linux 3.2"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:12.090","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98241","references":[{"url":"https://git.kernel.org/stable/c/4c030a0400ebfd2318361c923a88103b2c67c49f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60459c670329d586a58db5d8f811fa5accfe4862","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/675919e08ce266b8cac11fd9af29170e762a480f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6973a21ee73c5567f883813c8ef414774b45892f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/904a0e827d0d7189271a3a2eb648293809f25efc","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1a88633c36d2cbc3831382f3846754d344276fd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca3d68c3213475b53db6647e159dc73bd1af5ab1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.432Z","slug":"CVE-2026-98241","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nipv6: xfrm: use full sockets in local error paths\n\nxfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as if it\nalways pointed at a full IPv6 socket.\n\nThat is not guaranteed. TCP SYN-ACK skbs can be owned by a\nTCP_NEW_SYN_RECV request_sock while the output path itself is driven by the\nfull listener. If rerouting selects an IPv6 XFRM tunnel route with a lower\nMTU, the local PMTU/error handling path can reach these callbacks with that\nmini-socket still attached to the skb.\n\nThe callbacks then miscast the request socket as a full inet/IPv6 socket and\ncan read beyond the request_sock allocation when they access inet_sock or\nipv6_pinfo state.\n\nResolve the owner with skb_to_full_sk() in both callbacks and bail out when\nno full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error\nlogic, which already reasons about full sockets with skb_to_full_sk().\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}