---
id: CVE-2026-98288
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: stmmac: fix TSO header length truncation

  stmmac_tso_xmit() stores the protocol header length returned by
  stmmac_tso_header_size() in a u8
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: stmmac: fix TSO header length truncation

  stmmac_tso_xmit() stores the protocol header length returned by
  stmmac_tso_header_size() in a u8. stmmac_tso_valid_packet…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 9edfa7dab8112a012b349b7937f5444fdc21e8f9 <
    bcf6013c2b4d732c6e4bf4d0f6ae4a18d63d414b
  - >-
    Linux >= 9edfa7dab8112a012b349b7937f5444fdc21e8f9 <
    15989abd74f16f44bf953d056b95f1d2fda9b0cd
  - Linux 4.13
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:19.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98288'
references:
  - url: 'https://git.kernel.org/stable/c/15989abd74f16f44bf953d056b95f1d2fda9b0cd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bcf6013c2b4d732c6e4bf4d0f6ae4a18d63d414b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.418Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: stmmac: fix TSO header length truncation

stmmac_tso_xmit() stores the protocol header length returned by
stmmac_tso_header_size() in a u8. stmmac_tso_valid_packet() admits
headers up to 1023 bytes, so a header longer than 255 bytes wraps modulo
256 (486 becomes 230, 256 becomes 0).

A TCP over IPv6 socket carrying a few hundred bytes of sticky
destination/hop-by-hop options makes skb_tcp_all_headers() exceed 255
while staying below the 1023-byte limit, so such an skb reaches
stmmac_tso_xmit().

Widen proto_hdr_len to unsigned int, which is sufficient since the value
is bounded by the hardware limit, and adjust the debug print specifier
accordingly.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
