
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98240 is a buffer overflow vulnerability in the Linux kernel's net/ip_tunnel module caused by an uninitialized options_len counter during GENEVE tunnel option parsing. When a crafted ip route command with GENEVE encapsulation options is issued, the kernel's fortified memcpy() attempts a 4-byte write into a zero-sized destination buffer, triggering a kernel panic. The vulnerability affects Linux kernel version 6.15 (introduced at commit bb5e62f2d547) and is fixed in versions 6.18.54, 7.2.8, and 7.3-rc4. It is estimated as HIGH severity; a formal CVSS score has not yet been published (Feedly, ENISA EUVD).
The root cause is improper initialization of the options_len counter (CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer) in the ip_tun_parse_opts_geneve() function within the Linux kernel's IP tunnel subsystem. When parsing GENEVE options from a Netlink attribute (LWTUNNEL_IP_OPT_GENEVE_DATA), the code computes the destination pointer ip_tunnel_info_opts(info) + opts_len and calls memcpy(opt->opt_data, nla_data(attr), data_len) before options_len has been assigned its correct value — leaving the destination buffer effectively zero-sized. On kernels compiled with GCC 15+ and CONFIG_FORTIFY_SOURCE, the hardened memcpy() detects this as a buffer overflow and triggers a BUG() at lib/string_helpers.c:1044. The fix initializes options_len before any options are referenced, consistent with the approach already used in tunnel_key_opts_set() (Feedly, Kernel Patch 1).
Successful exploitation causes a kernel panic (system crash), resulting in a complete denial of service for the affected host. Any local user with sufficient privileges to configure network routes (typically requiring CAP_NET_ADMIN) can trigger the crash by issuing a crafted ip route add command with GENEVE encapsulation options. There is no evidence of confidentiality or integrity impact beyond the availability loss caused by the kernel panic (Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is 0.0, indicating very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and CAP_NET_ADMIN privileges, significantly limiting the attack surface (Feedly, ENISA EUVD).
CONFIG_FORTIFY_SOURCE, with CAP_NET_ADMIN privileges (e.g., root or a user in a network namespace with the capability).ip link add d0 type dummy && ip link set d0 up to establish a network interface to attach the route.ip route add 10.30.0.0/16 encap ip id 300 geneve_opts 4660:66:11223344 dev d0 to trigger GENEVE option parsing in ip_tun_parse_opts_geneve().options_len causes memcpy() to write 4 bytes into a zero-sized buffer; the fortified memcpy() detects the overflow and calls BUG(), crashing the kernel (Feedly)./var/log/kern.log or dmesg output containing memcpy: detected buffer overflow: 4 byte write of buffer size 0, kernel BUG at lib/string_helpers.c:1044, and stack traces referencing ip_tun_parse_opts.part.0.cold and ip_tun_build_state.auditd) showing execution of ip route add commands with encap ip and geneve_opts parameters by non-root users or unexpected accounts.CONFIG_FORTIFY_SOURCE enabled.Apply the upstream kernel patches fixing this issue: commit 9907325257b4 (stable branch), 0f6a6beb01c0 (stable branch), or 455ebeadf714 (stable branch), included in Linux kernel versions 6.18.54, 7.2.8, and 7.3-rc4 or later. As a workaround on unpatched systems, restrict CAP_NET_ADMIN to trusted users and limit the ability to configure GENEVE tunnel routes. Distributions shipping kernel 6.15.x should apply vendor-provided stable updates as soon as available (Feedly, Kernel Patch 1, Kernel Patch 2, Kernel Patch 3).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."