CVE-2026-98300 (GCVE-0-2026-98300)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:45 – Updated: 2026-10-06 08:45
VLAI
Title
tcp: Don't call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().
Summary
In the Linux kernel, the following vulnerability has been resolved: tcp: Don't call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv(). tcp_v6_do_rcv() no longer calls skb_clone_and_charge_r() for TCP_LISTEN since commit 073d89808c06 ("net: fix data-races around sk->sk_forward_alloc"). However, there is still a small race window between tcp_v6_rcv() and tcp_v6_do_rcv(), where concurrent close() changes TCP_LISTEN to TCP_CLOSE, causing skb_clone_and_charge_r() to be called locklessly and resulting in the splat below. [0] Let's avoid calling skb_clone_and_charge_r() for TCP_CLOSE as well. This is fine for non-listeners because tcp_rcv_state_process() drops skb for TCP_CLOSE and opt_skb was freed immediately anyway. [0]: sk->sk_forward_alloc WARNING: net/ipv4/af_inet.c:162 at inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162, CPU#1: ksoftirqd/1/28 Modules linked in: CPU: 1 UID: 0 PID: 28 Comm: ksoftirqd/1 Not tainted 7.2.0 #17 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-debian-1.17.0-1 04/01/2014 RIP: 0010:inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162 Code: 3d 49 ff e9 06 fd ff ff e8 d0 5b 83 f8 90 0f 0b 90 e9 35 fe ff ff e8 c2 5b 83 f8 90 0f 0b 90 e9 c5 fe ff ff e8 b4 5b 83 f8 90 <0f> 0b 90 e9 04 ff ff ff e8 a6 5b 83 f8 90 0f 0b 90 e9 65 fe ff ff RSP: 0018:ffffc90000677bb8 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffff8880117bde80 RCX: ffffffff8957eb41 RDX: ffff88801dad5d00 RSI: ffffffff8957ec3c RDI: 0000000000000005 RBP: 00000000fffff000 R08: ffffffff8957eb41 R09: 00000000fffff000 R10: 0000000000000005 R11: 0000000000000000 R12: dffffc0000000000 R13: ffff8880117bdf10 R14: ffffffff81c08eb7 R15: 0000000000000003 FS: 0000000000000000(0000) GS:ffff8880d7ae5000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f93a1021138 CR3: 00000000207a9000 CR4: 0000000000350ef0 Call Trace: <TASK> __sk_destruct+0x82/0xae0 net/core/sock.c:2356 rcu_do_batch kernel/rcu/tree.c:2645 [inline] rcu_core+0x59c/0x1100 kernel/rcu/tree.c:2897 handle_softirqs+0x1e4/0x9b0 kernel/softirq.c:622 run_ksoftirqd kernel/softirq.c:1076 [inline] run_ksoftirqd+0x38/0x60 kernel/softirq.c:1068 smpboot_thread_fn+0x458/0xc80 kernel/smpboot.c:160 kthread+0x396/0x4a0 kernel/kthread.c:436 ret_from_fork+0x8e0/0xe40 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK>
Severity
No CVSS data available.
Impacted products
Vendor Product Version
Linux Linux Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < a23a3bc5004df6434de05797e0b6b2ecf864b86a (git)
Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < 1cb7f292a337fdc72a8219bcd9d40a9cf5e86db5 (git)
Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < 7d94602e77a4525611afebb23149145ac242afd7 (git)
Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < b727e3d58cb906f1506c1334dfba71fbb1338339 (git)
Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < 3e3394a13b603cc79b6a35480b8e20df6c716944 (git)
Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < 619bfbaacbff6a9822923f69f6af29d7f66a870c (git)
Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < 56d38839ef0bff6526d9bd73b6811bd00316b21c (git)
Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < 8e759cd1f6444a946bd1fd2b2b29eea582eea1d5 (git)
Create a notification for this product.
Linux Linux Affected: 4.4
Unaffected: 0 , < 4.4 (semver)
Unaffected: 5.10.271 , ≤ 5.10.* (semver)
Unaffected: 5.15.222 , ≤ 5.15.* (semver)
Unaffected: 6.1.189 , ≤ 6.1.* (semver)
Unaffected: 6.6.158 , ≤ 6.6.* (semver)
Unaffected: 6.12.112 , ≤ 6.12.* (semver)
Unaffected: 6.18.54 , ≤ 6.18.* (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/ipv6/tcp_ipv6.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "a23a3bc5004df6434de05797e0b6b2ecf864b86a",
              "status": "affected",
              "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
              "versionType": "git"
            },
            {
              "lessThan": "1cb7f292a337fdc72a8219bcd9d40a9cf5e86db5",
              "status": "affected",
              "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
              "versionType": "git"
            },
            {
              "lessThan": "7d94602e77a4525611afebb23149145ac242afd7",
              "status": "affected",
              "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
              "versionType": "git"
            },
            {
              "lessThan": "b727e3d58cb906f1506c1334dfba71fbb1338339",
              "status": "affected",
              "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
              "versionType": "git"
            },
            {
              "lessThan": "3e3394a13b603cc79b6a35480b8e20df6c716944",
              "status": "affected",
              "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
              "versionType": "git"
            },
            {
              "lessThan": "619bfbaacbff6a9822923f69f6af29d7f66a870c",
              "status": "affected",
              "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
              "versionType": "git"
            },
            {
              "lessThan": "56d38839ef0bff6526d9bd73b6811bd00316b21c",
              "status": "affected",
              "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
              "versionType": "git"
            },
            {
              "lessThan": "8e759cd1f6444a946bd1fd2b2b29eea582eea1d5",
              "status": "affected",
              "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/ipv6/tcp_ipv6.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.4"
            },
            {
              "lessThan": "4.4",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.271",
                  "versionStartIncluding": "4.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.222",
                  "versionStartIncluding": "4.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.189",
                  "versionStartIncluding": "4.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.158",
                  "versionStartIncluding": "4.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.112",
                  "versionStartIncluding": "4.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.54",
                  "versionStartIncluding": "4.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "4.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "4.4",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Don\u0027t call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().\n\ntcp_v6_do_rcv() no longer calls skb_clone_and_charge_r() for\nTCP_LISTEN since commit 073d89808c06 (\"net: fix data-races around\nsk-\u003esk_forward_alloc\").\n\nHowever, there is still a small race window between tcp_v6_rcv()\nand tcp_v6_do_rcv(), where concurrent close() changes TCP_LISTEN\nto TCP_CLOSE, causing skb_clone_and_charge_r() to be called\nlocklessly and resulting in the splat below. [0]\n\nLet\u0027s avoid calling skb_clone_and_charge_r() for TCP_CLOSE as well.\n\nThis is fine for non-listeners because tcp_rcv_state_process()\ndrops skb for TCP_CLOSE and opt_skb was freed immediately anyway.\n\n[0]:\nsk-\u003esk_forward_alloc\nWARNING: net/ipv4/af_inet.c:162 at inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162, CPU#1: ksoftirqd/1/28\nModules linked in:\nCPU: 1 UID: 0 PID: 28 Comm: ksoftirqd/1 Not tainted 7.2.0 #17 PREEMPT(full)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\nRIP: 0010:inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162\nCode: 3d 49 ff e9 06 fd ff ff e8 d0 5b 83 f8 90 0f 0b 90 e9 35 fe ff ff e8 c2 5b 83 f8 90 0f 0b 90 e9 c5 fe ff ff e8 b4 5b 83 f8 90 \u003c0f\u003e 0b 90 e9 04 ff ff ff e8 a6 5b 83 f8 90 0f 0b 90 e9 65 fe ff ff\nRSP: 0018:ffffc90000677bb8 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffff8880117bde80 RCX: ffffffff8957eb41\nRDX: ffff88801dad5d00 RSI: ffffffff8957ec3c RDI: 0000000000000005\nRBP: 00000000fffff000 R08: ffffffff8957eb41 R09: 00000000fffff000\nR10: 0000000000000005 R11: 0000000000000000 R12: dffffc0000000000\nR13: ffff8880117bdf10 R14: ffffffff81c08eb7 R15: 0000000000000003\nFS:  0000000000000000(0000) GS:ffff8880d7ae5000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f93a1021138 CR3: 00000000207a9000 CR4: 0000000000350ef0\nCall Trace:\n \u003cTASK\u003e\n __sk_destruct+0x82/0xae0 net/core/sock.c:2356\n rcu_do_batch kernel/rcu/tree.c:2645 [inline]\n rcu_core+0x59c/0x1100 kernel/rcu/tree.c:2897\n handle_softirqs+0x1e4/0x9b0 kernel/softirq.c:622\n run_ksoftirqd kernel/softirq.c:1076 [inline]\n run_ksoftirqd+0x38/0x60 kernel/softirq.c:1068\n smpboot_thread_fn+0x458/0xc80 kernel/smpboot.c:160\n kthread+0x396/0x4a0 kernel/kthread.c:436\n ret_from_fork+0x8e0/0xe40 arch/x86/kernel/process.c:158\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n \u003c/TASK\u003e"
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-06T08:45:58.091Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a23a3bc5004df6434de05797e0b6b2ecf864b86a"
        },
        {
          "url": "https://git.kernel.org/stable/c/1cb7f292a337fdc72a8219bcd9d40a9cf5e86db5"
        },
        {
          "url": "https://git.kernel.org/stable/c/7d94602e77a4525611afebb23149145ac242afd7"
        },
        {
          "url": "https://git.kernel.org/stable/c/b727e3d58cb906f1506c1334dfba71fbb1338339"
        },
        {
          "url": "https://git.kernel.org/stable/c/3e3394a13b603cc79b6a35480b8e20df6c716944"
        },
        {
          "url": "https://git.kernel.org/stable/c/619bfbaacbff6a9822923f69f6af29d7f66a870c"
        },
        {
          "url": "https://git.kernel.org/stable/c/56d38839ef0bff6526d9bd73b6811bd00316b21c"
        },
        {
          "url": "https://git.kernel.org/stable/c/8e759cd1f6444a946bd1fd2b2b29eea582eea1d5"
        }
      ],
      "title": "tcp: Don\u0027t call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98300",
    "datePublished": "2026-10-06T08:45:58.091Z",
    "dateReserved": "2026-09-25T10:25:14.337Z",
    "dateUpdated": "2026-10-06T08:45:58.091Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98300",
      "date": "2026-10-08",
      "epss": "0.00176",
      "percentile": "0.06594"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "net/ipv6/tcp_ipv6.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "a23a3bc5004df6434de05797e0b6b2ecf864b86a",
                    "status": "affected",
                    "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "1cb7f292a337fdc72a8219bcd9d40a9cf5e86db5",
                    "status": "affected",
                    "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "7d94602e77a4525611afebb23149145ac242afd7",
                    "status": "affected",
                    "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b727e3d58cb906f1506c1334dfba71fbb1338339",
                    "status": "affected",
                    "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "3e3394a13b603cc79b6a35480b8e20df6c716944",
                    "status": "affected",
                    "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "619bfbaacbff6a9822923f69f6af29d7f66a870c",
                    "status": "affected",
                    "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "56d38839ef0bff6526d9bd73b6811bd00316b21c",
                    "status": "affected",
                    "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "8e759cd1f6444a946bd1fd2b2b29eea582eea1d5",
                    "status": "affected",
                    "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "net/ipv6/tcp_ipv6.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.4"
                  },
                  {
                    "lessThan": "4.4",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.10.*",
                    "status": "unaffected",
                    "version": "5.10.271",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.15.*",
                    "status": "unaffected",
                    "version": "5.15.222",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.189",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.158",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.112",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.54",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Don\u0027t call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().\n\ntcp_v6_do_rcv() no longer calls skb_clone_and_charge_r() for\nTCP_LISTEN since commit 073d89808c06 (\"net: fix data-races around\nsk-\u003esk_forward_alloc\").\n\nHowever, there is still a small race window between tcp_v6_rcv()\nand tcp_v6_do_rcv(), where concurrent close() changes TCP_LISTEN\nto TCP_CLOSE, causing skb_clone_and_charge_r() to be called\nlocklessly and resulting in the splat below. [0]\n\nLet\u0027s avoid calling skb_clone_and_charge_r() for TCP_CLOSE as well.\n\nThis is fine for non-listeners because tcp_rcv_state_process()\ndrops skb for TCP_CLOSE and opt_skb was freed immediately anyway.\n\n[0]:\nsk-\u003esk_forward_alloc\nWARNING: net/ipv4/af_inet.c:162 at inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162, CPU#1: ksoftirqd/1/28\nModules linked in:\nCPU: 1 UID: 0 PID: 28 Comm: ksoftirqd/1 Not tainted 7.2.0 #17 PREEMPT(full)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\nRIP: 0010:inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162\nCode: 3d 49 ff e9 06 fd ff ff e8 d0 5b 83 f8 90 0f 0b 90 e9 35 fe ff ff e8 c2 5b 83 f8 90 0f 0b 90 e9 c5 fe ff ff e8 b4 5b 83 f8 90 \u003c0f\u003e 0b 90 e9 04 ff ff ff e8 a6 5b 83 f8 90 0f 0b 90 e9 65 fe ff ff\nRSP: 0018:ffffc90000677bb8 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffff8880117bde80 RCX: ffffffff8957eb41\nRDX: ffff88801dad5d00 RSI: ffffffff8957ec3c RDI: 0000000000000005\nRBP: 00000000fffff000 R08: ffffffff8957eb41 R09: 00000000fffff000\nR10: 0000000000000005 R11: 0000000000000000 R12: dffffc0000000000\nR13: ffff8880117bdf10 R14: ffffffff81c08eb7 R15: 0000000000000003\nFS:  0000000000000000(0000) GS:ffff8880d7ae5000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f93a1021138 CR3: 00000000207a9000 CR4: 0000000000350ef0\nCall Trace:\n \u003cTASK\u003e\n __sk_destruct+0x82/0xae0 net/core/sock.c:2356\n rcu_do_batch kernel/rcu/tree.c:2645 [inline]\n rcu_core+0x59c/0x1100 kernel/rcu/tree.c:2897\n handle_softirqs+0x1e4/0x9b0 kernel/softirq.c:622\n run_ksoftirqd kernel/softirq.c:1076 [inline]\n run_ksoftirqd+0x38/0x60 kernel/softirq.c:1068\n smpboot_thread_fn+0x458/0xc80 kernel/smpboot.c:160\n kthread+0x396/0x4a0 kernel/kthread.c:436\n ret_from_fork+0x8e0/0xe40 arch/x86/kernel/process.c:158\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n \u003c/TASK\u003e"
          }
        ],
        "id": "CVE-2026-98300",
        "lastModified": "2026-10-06T09:18:20.867",
        "metrics": {},
        "published": "2026-10-06T09:18:20.867",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/1cb7f292a337fdc72a8219bcd9d40a9cf5e86db5"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/3e3394a13b603cc79b6a35480b8e20df6c716944"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/56d38839ef0bff6526d9bd73b6811bd00316b21c"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/619bfbaacbff6a9822923f69f6af29d7f66a870c"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/7d94602e77a4525611afebb23149145ac242afd7"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/8e759cd1f6444a946bd1fd2b2b29eea582eea1d5"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/a23a3bc5004df6434de05797e0b6b2ecf864b86a"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/b727e3d58cb906f1506c1334dfba71fbb1338339"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "low",
      "current_release_date": "2026-10-08T16:48:17Z",
      "cve": "CVE-2026-98300",
      "id": "CVE-2026-98300",
      "initial_release_date": "2026-10-08T16:48:17Z",
      "product_status:known_affected": "297",
      "product_status:known_not_affected": "50",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98300",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98300.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…