CVE-2026-98274: 
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-98274 is a security feature bypass vulnerability in the Linux kernel's networking subsystem, specifically involving a conflict between the PSP (Packet Stream Processing) and TLS ULP (Upper Layer Protocol) implementations. The vulnerability arises from both subsystems sharing usage of skb->decrypted and sk->sk_validate_xmit_skb(), leading to state corruption when both are configured on the same socket. It affects Linux kernel version 6.18 (introduced at commit 6b46ca260e2290e3453d1355ab5b6d283d73d780) and was published on October 6, 2026. The CVSS base score is reported as 0.0 with an estimated severity of Medium, and the EPSS score is 0.0 (GitHub Advisory, Feedly).

Technical details

The root cause is improper state management (related to CWE-362 or shared resource misuse) when PSP and TLS ULP are simultaneously active on a TCP socket — both subsystems attempt to control skb->decrypted (a per-packet decryption state flag) and sk->sk_validate_xmit_skb() (a transmit validation hook), resulting in conflicts and potential security bypasses. An attacker with local access and the ability to configure both PSP and TLS ULP on the same socket can corrupt the transmit validation state, causing unencrypted or improperly validated packets to be transmitted or received. The fix enforces mutual exclusivity between PSP and TLS ULP by extending the sk_has_decrypt_user() check to cover all TCP ULPs, preventing PSP from being configured alongside any ULP (GitHub Advisory).

Impact

Successful exploitation allows a local user to bypass encryption and transmit validation mechanisms, potentially causing unencrypted or improperly validated network packets to be sent or received on affected sockets. This primarily impacts confidentiality and integrity of network communications on systems using PSP alongside TLS ULP, as the expected cryptographic guarantees may be silently undermined. The vulnerability does not appear to enable remote code execution or privilege escalation, and its impact is limited to systems where both PSP and TLS ULP are in use (Feedly, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the publication date. The vulnerability requires local access and the ability to configure both PSP and TLS ULP on the same socket, which significantly limits the attack surface. The EPSS score is 0.0, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly, GitHub Advisory).

Mitigation and workarounds

Update the Linux kernel to a patched version: 6.18.54 or later for the 6.18.x branch, 7.2.8 or later for the 7.2.x branch, or 7.3-rc4 and later. The fix is also available via specific kernel commits: a13cca5ba5375f13cbdab545abfb5e288bef3f78, c8c8c18862337c469e325c207601de3279847809, and a41f24c612c3f5139a3143307eb85bbcf1bd4d07. As a configuration-based workaround, restrict socket configuration permissions to prevent simultaneous use of PSP and TLS ULP on the same socket (GitHub Advisory, Feedly).

Additional resources


Source: This report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98274NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesOct 06, 2026
CVE-2026-98259NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel6.18
NoYesOct 06, 2026
CVE-2026-98244NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel6.18
NoYesOct 06, 2026
CVE-2026-98240NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesOct 06, 2026
CVE-2026-98226NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management