CVE-2026-98288 (GCVE-0-2026-98288)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:45 – Updated: 2026-10-06 08:45
VLAI
Title
net: stmmac: fix TSO header length truncation
Summary
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TSO header length truncation stmmac_tso_xmit() stores the protocol header length returned by stmmac_tso_header_size() in a u8. stmmac_tso_valid_packet() admits headers up to 1023 bytes, so a header longer than 255 bytes wraps modulo 256 (486 becomes 230, 256 becomes 0). A TCP over IPv6 socket carrying a few hundred bytes of sticky destination/hop-by-hop options makes skb_tcp_all_headers() exceed 255 while staying below the 1023-byte limit, so such an skb reaches stmmac_tso_xmit(). Widen proto_hdr_len to unsigned int, which is sufficient since the value is bounded by the hardware limit, and adjust the debug print specifier accordingly.
Severity
No CVSS data available.
Impacted products
Vendor Product Version
Linux Linux Affected: 9edfa7dab8112a012b349b7937f5444fdc21e8f9 , < bcf6013c2b4d732c6e4bf4d0f6ae4a18d63d414b (git)
Affected: 9edfa7dab8112a012b349b7937f5444fdc21e8f9 , < 15989abd74f16f44bf953d056b95f1d2fda9b0cd (git)
Create a notification for this product.
Linux Linux Affected: 4.13
Unaffected: 0 , < 4.13 (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/stmicro/stmmac/stmmac_main.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "bcf6013c2b4d732c6e4bf4d0f6ae4a18d63d414b",
              "status": "affected",
              "version": "9edfa7dab8112a012b349b7937f5444fdc21e8f9",
              "versionType": "git"
            },
            {
              "lessThan": "15989abd74f16f44bf953d056b95f1d2fda9b0cd",
              "status": "affected",
              "version": "9edfa7dab8112a012b349b7937f5444fdc21e8f9",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/stmicro/stmmac/stmmac_main.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.13"
            },
            {
              "lessThan": "4.13",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: fix TSO header length truncation\n\nstmmac_tso_xmit() stores the protocol header length returned by\nstmmac_tso_header_size() in a u8. stmmac_tso_valid_packet() admits\nheaders up to 1023 bytes, so a header longer than 255 bytes wraps modulo\n256 (486 becomes 230, 256 becomes 0).\n\nA TCP over IPv6 socket carrying a few hundred bytes of sticky\ndestination/hop-by-hop options makes skb_tcp_all_headers() exceed 255\nwhile staying below the 1023-byte limit, so such an skb reaches\nstmmac_tso_xmit().\n\nWiden proto_hdr_len to unsigned int, which is sufficient since the value\nis bounded by the hardware limit, and adjust the debug print specifier\naccordingly."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-06T08:45:48.856Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bcf6013c2b4d732c6e4bf4d0f6ae4a18d63d414b"
        },
        {
          "url": "https://git.kernel.org/stable/c/15989abd74f16f44bf953d056b95f1d2fda9b0cd"
        }
      ],
      "title": "net: stmmac: fix TSO header length truncation",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98288",
    "datePublished": "2026-10-06T08:45:48.856Z",
    "dateReserved": "2026-09-25T10:25:14.336Z",
    "dateUpdated": "2026-10-06T08:45:48.856Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98288",
      "date": "2026-10-08",
      "epss": "0.00162",
      "percentile": "0.0487"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "drivers/net/ethernet/stmicro/stmmac/stmmac_main.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "bcf6013c2b4d732c6e4bf4d0f6ae4a18d63d414b",
                    "status": "affected",
                    "version": "9edfa7dab8112a012b349b7937f5444fdc21e8f9",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "15989abd74f16f44bf953d056b95f1d2fda9b0cd",
                    "status": "affected",
                    "version": "9edfa7dab8112a012b349b7937f5444fdc21e8f9",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "drivers/net/ethernet/stmicro/stmmac/stmmac_main.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.13"
                  },
                  {
                    "lessThan": "4.13",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: fix TSO header length truncation\n\nstmmac_tso_xmit() stores the protocol header length returned by\nstmmac_tso_header_size() in a u8. stmmac_tso_valid_packet() admits\nheaders up to 1023 bytes, so a header longer than 255 bytes wraps modulo\n256 (486 becomes 230, 256 becomes 0).\n\nA TCP over IPv6 socket carrying a few hundred bytes of sticky\ndestination/hop-by-hop options makes skb_tcp_all_headers() exceed 255\nwhile staying below the 1023-byte limit, so such an skb reaches\nstmmac_tso_xmit().\n\nWiden proto_hdr_len to unsigned int, which is sufficient since the value\nis bounded by the hardware limit, and adjust the debug print specifier\naccordingly."
          }
        ],
        "id": "CVE-2026-98288",
        "lastModified": "2026-10-06T09:18:19.030",
        "metrics": {},
        "published": "2026-10-06T09:18:19.030",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/15989abd74f16f44bf953d056b95f1d2fda9b0cd"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/bcf6013c2b4d732c6e4bf4d0f6ae4a18d63d414b"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "low",
      "current_release_date": "2026-10-08T16:48:32Z",
      "cve": "CVE-2026-98288",
      "id": "CVE-2026-98288",
      "initial_release_date": "2026-10-08T16:48:32Z",
      "product_status:known_affected": "254",
      "product_status:known_not_affected": "93",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98288",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98288.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…