CVE-2026-98240: 
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-98240 is a buffer overflow vulnerability in the Linux kernel's net/ip_tunnel module caused by an uninitialized options_len counter during GENEVE tunnel option parsing. When a crafted ip route command with GENEVE encapsulation options is issued, the kernel's fortified memcpy() attempts a 4-byte write into a zero-sized destination buffer, triggering a kernel panic. The vulnerability affects Linux kernel version 6.15 (introduced at commit bb5e62f2d547) and is fixed in versions 6.18.54, 7.2.8, and 7.3-rc4. It is estimated as HIGH severity; a formal CVSS score has not yet been published (Feedly, ENISA EUVD).

Technical details

The root cause is improper initialization of the options_len counter (CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer) in the ip_tun_parse_opts_geneve() function within the Linux kernel's IP tunnel subsystem. When parsing GENEVE options from a Netlink attribute (LWTUNNEL_IP_OPT_GENEVE_DATA), the code computes the destination pointer ip_tunnel_info_opts(info) + opts_len and calls memcpy(opt->opt_data, nla_data(attr), data_len) before options_len has been assigned its correct value — leaving the destination buffer effectively zero-sized. On kernels compiled with GCC 15+ and CONFIG_FORTIFY_SOURCE, the hardened memcpy() detects this as a buffer overflow and triggers a BUG() at lib/string_helpers.c:1044. The fix initializes options_len before any options are referenced, consistent with the approach already used in tunnel_key_opts_set() (Feedly, Kernel Patch 1).

Impact

Successful exploitation causes a kernel panic (system crash), resulting in a complete denial of service for the affected host. Any local user with sufficient privileges to configure network routes (typically requiring CAP_NET_ADMIN) can trigger the crash by issuing a crafted ip route add command with GENEVE encapsulation options. There is no evidence of confidentiality or integrity impact beyond the availability loss caused by the kernel panic (Feedly).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is 0.0, indicating very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and CAP_NET_ADMIN privileges, significantly limiting the attack surface (Feedly, ENISA EUVD).

Exploitation steps

  1. Precondition: Obtain local access to a vulnerable Linux system (kernel 6.15.x) compiled with GCC 15+ and CONFIG_FORTIFY_SOURCE, with CAP_NET_ADMIN privileges (e.g., root or a user in a network namespace with the capability).
  2. Create a dummy network interface: Run ip link add d0 type dummy && ip link set d0 up to establish a network interface to attach the route.
  3. Issue crafted ip route command: Execute ip route add 10.30.0.0/16 encap ip id 300 geneve_opts 4660:66:11223344 dev d0 to trigger GENEVE option parsing in ip_tun_parse_opts_geneve().
  4. Trigger kernel panic: The uninitialized options_len causes memcpy() to write 4 bytes into a zero-sized buffer; the fortified memcpy() detects the overflow and calls BUG(), crashing the kernel (Feedly).

Indicators of compromise

  • Logs: Kernel panic messages in /var/log/kern.log or dmesg output containing memcpy: detected buffer overflow: 4 byte write of buffer size 0, kernel BUG at lib/string_helpers.c:1044, and stack traces referencing ip_tun_parse_opts.part.0.cold and ip_tun_build_state.
  • Process/Command: Audit logs (auditd) showing execution of ip route add commands with encap ip and geneve_opts parameters by non-root users or unexpected accounts.
  • System: Unexpected system reboots or crash dumps (kdump) on hosts running Linux kernel 6.15.x with CONFIG_FORTIFY_SOURCE enabled.

Mitigation and workarounds

Apply the upstream kernel patches fixing this issue: commit 9907325257b4 (stable branch), 0f6a6beb01c0 (stable branch), or 455ebeadf714 (stable branch), included in Linux kernel versions 6.18.54, 7.2.8, and 7.3-rc4 or later. As a workaround on unpatched systems, restrict CAP_NET_ADMIN to trusted users and limit the ability to configure GENEVE tunnel routes. Distributions shipping kernel 6.15.x should apply vendor-provided stable updates as soon as available (Feedly, Kernel Patch 1, Kernel Patch 2, Kernel Patch 3).

Additional resources


Source: This report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98274NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesOct 06, 2026
CVE-2026-98259NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel6.18
NoYesOct 06, 2026
CVE-2026-98244NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel6.18
NoYesOct 06, 2026
CVE-2026-98240NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesOct 06, 2026
CVE-2026-98226NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management