CVE-2026-98097EPSS p7.2%
CVE-2026-98097CVE-2026-98097
Description
In the Linux kernel, the following vulnerability has been resolved:
tipc: Dont send random pad bytes in RESET/ACTIVATE messages
The interface name is passed in a fixed length (TIPC_MAX_IF_NAME) buffer.
Replace the strcpy(data, l->if_name) with memcpy() so that the
pad bytes are actually written (l->if_name[] is zero padded)
rather than sending random bytes from the skb to the remote system.
Replace two other strcpy() with strscpy().
Scoring
| EPSS | 0.18% probability of exploitation · percentile 7.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |