CVE-2026-98372: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-98372 is a stack out-of-bounds read vulnerability in the Linux kernel's xfrm IPTFS (IP Traffic Flow Security) subsystem, specifically in the iptfs_skb_reset_frag_walk() function. It affects Linux kernel versions starting from 6.14 up to (but not including) the patched stable commits, and was published on October 6, 2026. The vulnerability allows an unauthenticated network attacker to trigger a read of arbitrary stack memory by delivering a crafted IP-TFS (AGGFRAG) payload to a system with an IPTFS Security Association configured. The CVSS category is estimated as Medium (Feedly, GitHub Advisory).

Technical details

The root cause is an unbounded loop in iptfs_skb_reset_frag_walk() (net/xfrm/xfrm_iptfs.c) that advances a fragment index (walk->fragi) without ever validating it against walk->nr_frags. When the requested offset equals or exceeds the total length spanned by the walk's fragments, fragi increments past nr_frags and dereferences beyond the end of the fixed-size on-stack frags[MAX_SKB_FRAGS + 1] array, resulting in a stack out-of-bounds read (CWE class: out-of-bounds read). The caller iptfs_skb_can_add_frags() invokes iptfs_skb_reset_frag_walk() unconditionally without the offset guard that its sibling iptfs_skb_add_frags() already implements; its own fragi < walk->nr_frags check runs only after the out-of-bounds access has already occurred. The exploit path is: crafted AGGFRAG payload → iptfs_reassem_cont() → iptfs_skb_can_add_frags() → iptfs_skb_reset_frag_walk() with an out-of-range offset (GitHub Advisory).

Impact

Successful exploitation causes the kernel to read arbitrary stack memory adjacent to the frags array, constituting a memory disclosure (information leak) from kernel space. An unauthenticated remote attacker who can deliver crafted ESP/IP-TFS packets to a system with an IPTFS Security Association enabled can potentially leak sensitive kernel stack data, which could include cryptographic material, pointers useful for bypassing KASLR, or other privileged information. While the immediate impact is confidentiality loss, leaked pointer values could facilitate further exploitation in a chained attack (Feedly, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The vulnerability is reachable from the network receive path without authentication, but requires the target system to have an IPTFS (IP Traffic Flow Security) Security Association configured, which is a relatively uncommon deployment. No threat actor attribution, EPSS score, or CISA KEV catalog entry has been reported for this CVE.

Exploitation steps

  1. Reconnaissance: Identify target systems running Linux kernel 6.14 or later with an IPTFS (IP Traffic Flow Security / AGGFRAG mode) IPsec Security Association configured. This typically requires knowledge of the target's IPsec configuration.
  2. Craft malicious AGGFRAG payload: Construct an IP-TFS (AGGFRAG) ESP packet where the inner fragment offset value exceeds the total length of the fragments described in the packet, causing the walk offset to be out of range.
  3. Deliver the packet: Send the crafted ESP packet to the target system's IP address on the appropriate interface. Since this is processed in the kernel's receive path, no authentication beyond network reachability is required.
  4. Trigger OOB read: The kernel processes the packet via iptfs_input() → iptfs_input_ordered() → iptfs_reassem_cont() → iptfs_skb_can_add_frags() → iptfs_skb_reset_frag_walk(), where the unbounded loop reads past the end of the on-stack frags array.
  5. Leak stack memory: Depending on the kernel's error handling and any side-channel or response observable to the attacker, adjacent stack memory contents may be disclosed, potentially including kernel pointers or sensitive data (GitHub Advisory).

Indicators of compromise

  • Logs: Kernel KASAN reports such as BUG: KASAN: stack-out-of-bounds in iptfs_skb_reset_frag_walk+0x235/0x250 in dmesg or kernel logs; stack traces referencing iptfs_skb_reset_frag_walk, iptfs_skb_can_add_frags, iptfs_reassem_cont, iptfs_input_ordered, iptfs_input, xfrm_input, xfrm4_esp_rcv in sequence.
  • Network: Unusual or malformed ESP/AGGFRAG packets arriving on IPsec interfaces with fragment offsets exceeding the declared fragment total; unexpected volume of ESP packets from unknown or untrusted peers targeting IPTFS SAs.
  • Process/Kernel: Kernel oops or panic events originating from net/xfrm/xfrm_iptfs.c around line 392 (iptfs_skb_reset_frag_walk) or line 420 (iptfs_skb_can_add_frags) (GitHub Advisory).

Mitigation and workarounds

Apply the upstream kernel patches that add an offset bounds check to iptfs_skb_can_add_frags() before calling iptfs_skb_reset_frag_walk(), mirroring the guard already present in iptfs_skb_add_frags(). The fixes are available in stable commits 7e1c6884a0b4, da56d0ee93d1, and d042487dc118; patched stable releases include kernel 6.18.54 and 7.2.8 and later (GitHub Advisory). As a workaround, disable IPTFS (IP Traffic Flow Security) if it is not required in your deployment, which eliminates the vulnerable code path entirely (Feedly).

Additional resources


Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98372NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98371NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98370NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98369NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98368NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management