
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98372 is a stack out-of-bounds read vulnerability in the Linux kernel's xfrm IPTFS (IP Traffic Flow Security) subsystem, specifically in the iptfs_skb_reset_frag_walk() function. It affects Linux kernel versions starting from 6.14 up to (but not including) the patched stable commits, and was published on October 6, 2026. The vulnerability allows an unauthenticated network attacker to trigger a read of arbitrary stack memory by delivering a crafted IP-TFS (AGGFRAG) payload to a system with an IPTFS Security Association configured. The CVSS category is estimated as Medium (Feedly, GitHub Advisory).
The root cause is an unbounded loop in iptfs_skb_reset_frag_walk() (net/xfrm/xfrm_iptfs.c) that advances a fragment index (walk->fragi) without ever validating it against walk->nr_frags. When the requested offset equals or exceeds the total length spanned by the walk's fragments, fragi increments past nr_frags and dereferences beyond the end of the fixed-size on-stack frags[MAX_SKB_FRAGS + 1] array, resulting in a stack out-of-bounds read (CWE class: out-of-bounds read). The caller iptfs_skb_can_add_frags() invokes iptfs_skb_reset_frag_walk() unconditionally without the offset guard that its sibling iptfs_skb_add_frags() already implements; its own fragi < walk->nr_frags check runs only after the out-of-bounds access has already occurred. The exploit path is: crafted AGGFRAG payload → iptfs_reassem_cont() → iptfs_skb_can_add_frags() → iptfs_skb_reset_frag_walk() with an out-of-range offset (GitHub Advisory).
Successful exploitation causes the kernel to read arbitrary stack memory adjacent to the frags array, constituting a memory disclosure (information leak) from kernel space. An unauthenticated remote attacker who can deliver crafted ESP/IP-TFS packets to a system with an IPTFS Security Association enabled can potentially leak sensitive kernel stack data, which could include cryptographic material, pointers useful for bypassing KASLR, or other privileged information. While the immediate impact is confidentiality loss, leaked pointer values could facilitate further exploitation in a chained attack (Feedly, GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The vulnerability is reachable from the network receive path without authentication, but requires the target system to have an IPTFS (IP Traffic Flow Security) Security Association configured, which is a relatively uncommon deployment. No threat actor attribution, EPSS score, or CISA KEV catalog entry has been reported for this CVE.
iptfs_input() → iptfs_input_ordered() → iptfs_reassem_cont() → iptfs_skb_can_add_frags() → iptfs_skb_reset_frag_walk(), where the unbounded loop reads past the end of the on-stack frags array.BUG: KASAN: stack-out-of-bounds in iptfs_skb_reset_frag_walk+0x235/0x250 in dmesg or kernel logs; stack traces referencing iptfs_skb_reset_frag_walk, iptfs_skb_can_add_frags, iptfs_reassem_cont, iptfs_input_ordered, iptfs_input, xfrm_input, xfrm4_esp_rcv in sequence.net/xfrm/xfrm_iptfs.c around line 392 (iptfs_skb_reset_frag_walk) or line 420 (iptfs_skb_can_add_frags) (GitHub Advisory).Apply the upstream kernel patches that add an offset bounds check to iptfs_skb_can_add_frags() before calling iptfs_skb_reset_frag_walk(), mirroring the guard already present in iptfs_skb_add_frags(). The fixes are available in stable commits 7e1c6884a0b4, da56d0ee93d1, and d042487dc118; patched stable releases include kernel 6.18.54 and 7.2.8 and later (GitHub Advisory). As a workaround, disable IPTFS (IP Traffic Flow Security) if it is not required in your deployment, which eliminates the vulnerable code path entirely (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."