Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98287— pppoatm: ensure a writable skb header and linear data

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: pppoatm:确保 skb 头部可写且数据线性 在 函数中,LLC 封装会检查是否有足够的头部空间(headroom)来容纳 4 字节的 LLC 头,但并未确保 skb 头部是可写的。 正常通过 发送的数据包会经由 确保其头部未被共享(即具有可写副本)。然而,数据包也可能通过 PPP 通道桥接(PPPIOCBRIDGECHAN)直接到达 ,而无需经过 。 因此,在添加 LLC 头之前,应使用 来确保同时具备足够的头部空间和可写的头部。 此外,还进行了以下改进: 在检查

AI Predicted 6.5 Difficulty: Moderate EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux 4cf476ced45d7f12df30a68e833b263e7a2202d1< 208ccc4d08b1897451e9ba01c016bf93ff107966 affected
4cf476ced45d7f12df30a68e833b263e7a2202d1< e6cd1bba7d113c15c00ac63671213a096fe4d686 affected
4cf476ced45d7f12df30a68e833b263e7a2202d1< ffc448eb54f5ba80d4212c1e870cdb92b0f709fa affected
4cf476ced45d7f12df30a68e833b263e7a2202d1< 8e66c5969acd859ba72fb0a7fa895623fc1b3769 affected
4cf476ced45d7f12df30a68e833b263e7a2202d1< e2f5529b0016db7d34f411408607f5cf395a542e affected
4cf476ced45d7f12df30a68e833b263e7a2202d1< 30992fe39e65589ed8e000425e088fa74994b811 affected
4cf476ced45d7f12df30a68e833b263e7a2202d1< ecc7253683a3c55caa868ce0ee530fcb0044bd3c affected
5.11 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98287

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
pppoatm: ensure a writable skb header and linear data
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: pppoatm: ensure a writable skb header and linear data In pppoatm_send(), LLC encapsulation checks whether there is sufficient headroom for the 4-byte LLC header, but does not ensure that the skb header is writable. Normal transmit packets passing through ppp_start_xmit() have their header unshared via skb_cow_head(). However, packets can also reach pppoatm_send() via PPP channel bridging (PPPIOCBRIDGECHAN) without going through ppp_start_xmit(). Use skb_cow_head() to ensure both sufficient headroom and a writable header before pushing the LLC header. While at it: - Call pskb_may_pull(skb, 1) before inspecting skb->data[0] to prevent out-of-bounds reads on zero-length or non-linear frames (e.g. from bridging). - Defer SC_COMP_PROT protocol compression until after pppoatm_may_send() succeeds. This eliminates the temporary skb allocation on admission failure and completely removes the fragile "undo" heuristic at the nospace label, avoiding any risk of reading uninitialized headroom or performing an unbalanced skb_push().
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 4cf476ced45d7f12df30a68e833b263e7a2202d1 ~ 208ccc4d08b1897451e9ba01c016bf93ff107966 -
Linux Linux 5.11 -

II. Public POCs for CVE-2026-98287

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98287

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98287 (7)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98305 7.8 HIGH net: dsa: mxl862xx: disable the stats poll on teardown
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98287

No comments yet


Leave a comment