CVE-2026-98371: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-98371 is a denial-of-service vulnerability in the Linux kernel's IPTFS (IP Tunnel Fast Forwarding / xfrm iptfs) packet reassembly implementation, capable of triggering an unprivileged kernel panic (skb_over_panic). The flaw was discovered by the autokbug dynamic kernel fuzzer at Tencent Yunding Lab and disclosed on October 6, 2026. It affects Linux kernel version 6.14 (introduced at commit 07569476544681816335099929ff3494dfbf6b05); versions prior to 6.14 and patched stable releases (≥6.18.54, ≥7.2.8, and 7.3-rc4+) are unaffected. The CVSS category is estimated as Medium (GitHub Advisory, Feedly).

Technical details

The root cause is insufficient input validation (improper bounds checking) in the IPTFS runt packet reassembly path within net/xfrm/xfrm_iptfs.c. When an inner packet's start is split across two outer IPTFS packets with fewer than 4 bytes landing at the end of the first, __input_process_payload() stores those bytes as a "runt" and bypasses the iplen/iphlen validation applied to normal in-place packets. Upon arrival of the continuation packet, iptfs_reassem_cont() only requires the attacker-controlled declared inner length to be >= sizeof(ra_runt) (6 bytes) before allocating the reassembly socket buffer (skb). Because __iptfs_iphlen() always returns the fixed minimum IP header size (20 bytes for IPv4, 40 for IPv6), an inner IPv4 tot_len in the range [6, 19] causes the header-completion copy to write past the declared packet length; the subsequent ipremain -= copylen operation then underflows to approximately 4 GB, leaving the payload copy length bounded only by blkoff (up to 64 KB). At runtime, the skb_put() tailroom check converts this into skb_over_panic(). The fix aligns the runt path with the normal path by requiring the declared inner length to be at least the minimum IP header size, subsuming the prior >= sizeof(ra_runt) check (GitHub Advisory).

Impact

Successful exploitation results in a kernel panic (skb_over_panic) — a complete system crash — constituting a Denial of Service (DoS) with high availability impact. The vulnerability is reachable both locally (via unprivileged user namespaces and network namespaces with IPTFS Security Associations) and remotely against IPTFS VPN gateways when the decrypted outer skb is linear, such as through AF_PACKET taps or tun/tap delivery. There is no evidence of confidentiality or integrity impact beyond the system crash (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack is notable because it is reachable by unprivileged local users (via userns+netns) and remotely against exposed IPTFS VPN gateways without authentication, lowering the bar for exploitation if a PoC were to emerge. The vulnerability was discovered through dynamic kernel fuzzing (autokbug) at Tencent Yunding Lab (GitHub Advisory, Feedly).

Exploitation steps

  1. Identify a target: Locate a system running Linux kernel 6.14 (between commits 07569476544681816335099929ff3494dfbf6b05 and the fix commits) with IPTFS Security Associations (SAs) configured — either a local system with unprivileged user namespace access or a remote IPTFS VPN gateway.
  2. Set up IPTFS SA access: Locally, create a user namespace and network namespace (unshare -Unr) and configure an IPTFS SA. Remotely, craft packets destined for an exposed IPTFS VPN gateway.
  3. Craft a malformed outer packet (first fragment): Construct an outer IPTFS packet where the start of an inner IPv4 packet is included, but only 1–3 bytes of the inner packet's header land at the end of the outer packet. This causes the kernel to save those bytes as a "runt" and skip iplen/iphlen validation.
  4. Craft the continuation packet with a short tot_len: Send a second outer IPTFS packet continuing the inner packet, with the inner IPv4 tot_len field set to a value in the range [6, 19] (i.e., ≥ sizeof(ra_runt) but less than the minimum IPv4 header size of 20 bytes).
  5. Trigger the integer underflow and kernel panic: The kernel allocates a reassembly skb sized to the attacker-controlled tot_len, then copies the minimum IP header size (20 bytes) into it, writing past the buffer end. The ipremain -= copylen operation underflows to ~4 GB, and the subsequent skb_put() call triggers skb_over_panic(), crashing the kernel (GitHub Advisory, Feedly).

Indicators of compromise

  • Logs: Kernel logs (dmesg / /var/log/kern.log) containing skb_over_panic or kernel BUG at net/core/skbuff.c immediately following IPTFS packet processing; stack traces referencing iptfs_reassem_cont, __input_process_payload, or xfrm_iptfs.
  • Network: Unusual IPTFS-encapsulated traffic (ESP packets with IPTFS inner structure) containing inner IPv4 packets with tot_len values between 6 and 19 bytes; repeated short-fragment IPTFS outer packets from the same source IP targeting a VPN gateway.
  • System Behavior: Unexpected system reboots or kernel panics on hosts running IPTFS VPN configurations; crash dump files (vmcore) generated around the time of suspicious IPTFS traffic.

Mitigation and workarounds

Apply the upstream kernel patches that fix the runt reassembly path: commits a7018ee0ea8622ed59edc064be4e0f2c26464f53, 5b8afb56ccb7c014b0f1ac40341708b200443c2d, and dc33262be1fe43d0eb0b84fb58c6ed42e2f64a8c for the stable trees. Fixed stable releases include Linux 6.18.54 and 7.2.8; the fix is also present in 7.3-rc4 and later. As interim workarounds: restrict IPTFS SA creation to privileged users (disable unprivileged user namespaces via sysctl kernel.unprivileged_userns_clone=0 where supported), and implement network segmentation to limit untrusted access to IPTFS VPN gateway interfaces (GitHub Advisory, Feedly).

Community reactions

The vulnerability was announced via the official Linux kernel CVE mailing list (lore.kernel.org/linux-cve-announce) on October 6, 2026, and credited to Tencent Yunding Lab's autokbug dynamic kernel fuzzer. No significant broader media coverage or notable researcher commentary beyond the kernel announcement has been observed at this time (Linux Kernel Announce).

Additional resources


Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98372NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98371NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98370NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98369NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98368NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management