---
id: CVE-2026-98089
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bonding: alb: fix uninitialized transport header access in alb_determine_nd()

  alb_determine_nd() uses icmp6_hdr(skb) to inspect ICMPv6 headers.
  However, in xmit paths …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bonding: alb: fix uninitialized transport header access in alb_determine_nd()

  alb_determine_nd() uses icmp6_hdr(skb) to inspect ICMPv6 headers.
  However, in xmit paths …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 0da8aa00bfcfeb3f4e6537dd8e2001e0727ba549 <
    e39cf90bd856443542b97933289749fca07476bf
  - >-
    Linux >= 0da8aa00bfcfeb3f4e6537dd8e2001e0727ba549 <
    27314f96d29b54e815e7a9b84c3273f1895e68e2
  - >-
    Linux >= 0da8aa00bfcfeb3f4e6537dd8e2001e0727ba549 <
    3b178894931a268c09126a5b53630f343e10e296
  - >-
    Linux >= 0da8aa00bfcfeb3f4e6537dd8e2001e0727ba549 <
    70f3995830d3f1e79faa14eb0605914f778feca9
  - Linux 5.18
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:38.590'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98089'
references:
  - url: 'https://git.kernel.org/stable/c/27314f96d29b54e815e7a9b84c3273f1895e68e2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3b178894931a268c09126a5b53630f343e10e296'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/70f3995830d3f1e79faa14eb0605914f778feca9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e39cf90bd856443542b97933289749fca07476bf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.832Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

bonding: alb: fix uninitialized transport header access in alb_determine_nd()

alb_determine_nd() uses icmp6_hdr(skb) to inspect ICMPv6 headers.
However, in xmit paths (e.g. packets sent via AF_PACKET / raw sockets
or forwarded packets), skb->transport_header is not guaranteed to be
initialized. While pskb_network_may_pull() ensures the packet data is
linear starting from the network header, it does not set or adjust the
transport header offset.

Dereferencing icmp6_hdr(skb) can therefore access out-of-bounds memory.

Fetch the icmp6hdr directly after ipv6hdr following pskb_network_may_pull(),
and reload ipv6hdr in case pskb_may_pull() reallocated skb->head.
Also remove the unused bond argument from alb_determine_nd().

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
