
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98371 is a denial-of-service vulnerability in the Linux kernel's IPTFS (IP Tunnel Fast Forwarding / xfrm iptfs) packet reassembly implementation, capable of triggering an unprivileged kernel panic (skb_over_panic). The flaw was discovered by the autokbug dynamic kernel fuzzer at Tencent Yunding Lab and disclosed on October 6, 2026. It affects Linux kernel version 6.14 (introduced at commit 07569476544681816335099929ff3494dfbf6b05); versions prior to 6.14 and patched stable releases (≥6.18.54, ≥7.2.8, and 7.3-rc4+) are unaffected. The CVSS category is estimated as Medium (GitHub Advisory, Feedly).
The root cause is insufficient input validation (improper bounds checking) in the IPTFS runt packet reassembly path within net/xfrm/xfrm_iptfs.c. When an inner packet's start is split across two outer IPTFS packets with fewer than 4 bytes landing at the end of the first, __input_process_payload() stores those bytes as a "runt" and bypasses the iplen/iphlen validation applied to normal in-place packets. Upon arrival of the continuation packet, iptfs_reassem_cont() only requires the attacker-controlled declared inner length to be >= sizeof(ra_runt) (6 bytes) before allocating the reassembly socket buffer (skb). Because __iptfs_iphlen() always returns the fixed minimum IP header size (20 bytes for IPv4, 40 for IPv6), an inner IPv4 tot_len in the range [6, 19] causes the header-completion copy to write past the declared packet length; the subsequent ipremain -= copylen operation then underflows to approximately 4 GB, leaving the payload copy length bounded only by blkoff (up to 64 KB). At runtime, the skb_put() tailroom check converts this into skb_over_panic(). The fix aligns the runt path with the normal path by requiring the declared inner length to be at least the minimum IP header size, subsuming the prior >= sizeof(ra_runt) check (GitHub Advisory).
Successful exploitation results in a kernel panic (skb_over_panic) — a complete system crash — constituting a Denial of Service (DoS) with high availability impact. The vulnerability is reachable both locally (via unprivileged user namespaces and network namespaces with IPTFS Security Associations) and remotely against IPTFS VPN gateways when the decrypted outer skb is linear, such as through AF_PACKET taps or tun/tap delivery. There is no evidence of confidentiality or integrity impact beyond the system crash (GitHub Advisory, Feedly).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack is notable because it is reachable by unprivileged local users (via userns+netns) and remotely against exposed IPTFS VPN gateways without authentication, lowering the bar for exploitation if a PoC were to emerge. The vulnerability was discovered through dynamic kernel fuzzing (autokbug) at Tencent Yunding Lab (GitHub Advisory, Feedly).
07569476544681816335099929ff3494dfbf6b05 and the fix commits) with IPTFS Security Associations (SAs) configured — either a local system with unprivileged user namespace access or a remote IPTFS VPN gateway.unshare -Unr) and configure an IPTFS SA. Remotely, craft packets destined for an exposed IPTFS VPN gateway.iplen/iphlen validation.tot_len: Send a second outer IPTFS packet continuing the inner packet, with the inner IPv4 tot_len field set to a value in the range [6, 19] (i.e., ≥ sizeof(ra_runt) but less than the minimum IPv4 header size of 20 bytes).skb sized to the attacker-controlled tot_len, then copies the minimum IP header size (20 bytes) into it, writing past the buffer end. The ipremain -= copylen operation underflows to ~4 GB, and the subsequent skb_put() call triggers skb_over_panic(), crashing the kernel (GitHub Advisory, Feedly).dmesg / /var/log/kern.log) containing skb_over_panic or kernel BUG at net/core/skbuff.c immediately following IPTFS packet processing; stack traces referencing iptfs_reassem_cont, __input_process_payload, or xfrm_iptfs.tot_len values between 6 and 19 bytes; repeated short-fragment IPTFS outer packets from the same source IP targeting a VPN gateway.vmcore) generated around the time of suspicious IPTFS traffic.Apply the upstream kernel patches that fix the runt reassembly path: commits a7018ee0ea8622ed59edc064be4e0f2c26464f53, 5b8afb56ccb7c014b0f1ac40341708b200443c2d, and dc33262be1fe43d0eb0b84fb58c6ed42e2f64a8c for the stable trees. Fixed stable releases include Linux 6.18.54 and 7.2.8; the fix is also present in 7.3-rc4 and later. As interim workarounds: restrict IPTFS SA creation to privileged users (disable unprivileged user namespaces via sysctl kernel.unprivileged_userns_clone=0 where supported), and implement network segmentation to limit untrusted access to IPTFS VPN gateway interfaces (GitHub Advisory, Feedly).
The vulnerability was announced via the official Linux kernel CVE mailing list (lore.kernel.org/linux-cve-announce) on October 6, 2026, and credited to Tencent Yunding Lab's autokbug dynamic kernel fuzzer. No significant broader media coverage or notable researcher commentary beyond the kernel announcement has been observed at this time (Linux Kernel Announce).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."