Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98096— ipv6: sr: restore network header before routing and forwarding

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: ipv6: sr: 在路由和转发之前恢复网络头 函数执行时, 指向 Segment Routing Header (SRH,分段路由头),而 指向 IPv6 头部。 当 (剩余分段数大于 0)时, 之前通过增加 的大小来恢复 的位置,该假设认为 SRH 紧随固定的 IPv6 头部之后。然而,如果 SRH 之前存在其他扩展头(例如 Hop-by-Hop Options Header,逐跳选项头),则 会保持为负值。 这导致两个问题: 1. 在 期间, 调用 ,后者将负的 传递

CVSS 7.4 · High EPSS 0.51% · P42

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 1ababeba4a21f3dba3da3523c670b207fb2feb62< f463c4786cf27376de7dfc0833a12e924a98f698 affected
1ababeba4a21f3dba3da3523c670b207fb2feb62< 8f44d4160bcdb3136a9145a4b9c7816382976925 affected
1ababeba4a21f3dba3da3523c670b207fb2feb62< 9cfbe2c381ab6d00a08e7a5b6028865adfb4e1bc affected
1ababeba4a21f3dba3da3523c670b207fb2feb62< af08f62b5a5a446d6134a92d86771d3d12e0e3da affected
1ababeba4a21f3dba3da3523c670b207fb2feb62< ce4c8beedc19aceeab0e7bdc6f34394fb158c47c affected
1ababeba4a21f3dba3da3523c670b207fb2feb62< 97b21ef57dfabbff660a4672c9fef7edfb720f47 affected
1ababeba4a21f3dba3da3523c670b207fb2feb62< 3ad7dca5e03bd64c65983a19734337512fd75491 affected
1ababeba4a21f3dba3da3523c670b207fb2feb62< 975b5b067f525a1b1338c4a3bee1c46545801518 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98096

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ipv6: sr: restore network header before routing and forwarding
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: restore network header before routing and forwarding ipv6_srh_rcv() runs with skb->data at the Segment Routing Header (SRH) while skb_network_header() points at the IPv6 header. When segments_left > 0, ipv6_srh_rcv() previously restored the skb->data position by pushing sizeof(struct ipv6hdr), assuming the SRH immediately followed the fixed IPv6 header. If another extension header (such as a Hop-by-Hop options header) precedes the SRH, skb_network_offset() remained negative. This led to two problems: 1. During ip6_route_input(), fib6_rules_early_flow_dissect() invokes __skb_flow_dissect() which passes the negative skb_network_offset() to flow dissection, breaking BPF and C flow dissector logic. 2. If forwarded via ip6_forward() or redirected via act_mirred, downstream handlers (like sch_fragment() or neighbour output) pass the negative offset as an unsigned length, triggering OOB memcpy or buffer overflows. Fix this by pushing -skb_network_offset(skb) before routing, ensuring skb_network_offset(skb) is 0 for route lookup / flow dissection as well as downstream forwarding. On the loopback path, pull skb_transport_offset(skb) to restore skb->data to the SRH before looping back.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 1ababeba4a21f3dba3da3523c670b207fb2feb62 ~ f463c4786cf27376de7dfc0833a12e924a98f698 -
Linux Linux 4.10 -

II. Public POCs for CVE-2026-98096

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98096

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98096 (8)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98122 7.8 HIGH vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()
CVE-2026-97575 7.8 HIGH media: v4l2-ctrls: validate AV1 tile counts
CVE-2026-97576 7.8 HIGH media: v4l2-ctrls: validate HEVC tile counts
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events
CVE-2026-98002 7.8 HIGH iommu/amd: Fix ineffective error check in nested domain allocation
CVE-2026-98116 7.8 HIGH ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
CVE-2026-97580 7.8 HIGH media: rkvdec: bound HEVC tile loops and PPS id to the array capacity
CVE-2026-97940 7.8 HIGH ipv6: fix fib6 walker UAF on seq stop

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98096

No comments yet


Leave a comment