CVE-2026-98233EPSS p6.6%
CVE-2026-98233CVE-2026-98233
Description
In the Linux kernel, the following vulnerability has been resolved:
net/packet: clear RX owner on VNET header error
Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race
condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2
ring slot before converting the virtio-net header. If the conversion
fails, the drop path leaves the slot claimed.
With a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves
the only slot unavailable, so the ring also drops the next valid packet.
Clear the ownership bit on this error path. TPACKET_V3 already clears
its block state here.
Scoring
| EPSS | 0.18% probability of exploitation · percentile 6.6% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-06 |