CVE-2026-98233: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net/packet: clear RX owner on VNET header error Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2 ring slot before converting the virtio-net header. If the conversion fails, the drop path leaves the slot claimed. With a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves the only slot unavailable, so the ring also drops the next valid packet. Clear the ownership bit on this error path. TPACKET_V3 already clears its block state here.
Affected products
- Linux Linux: from 4.14.175, before 4.15 (fixed in 4.15); from 4.19.114, before 4.20 (fixed in 4.20); from 5.4.29, before 5.5 (fixed in 5.5); from 5.5.14, before 5.6 (fixed in 5.6); from 5.6, before 5.10.271 (fixed in 5.10.271); from 5.11, before 5.15.222 (fixed in 5.15.222); …
Published 2026-10-06. Last modified 2026-10-06.