CVE-2026-98233: net/packet: clear RX owner on VNET header error

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net/packet: clear RX owner on VNET header error

Commit 61fad6816fc1 ("net/packet: tpacketrcv: avoid a producer race condition") added rxownermap and made tpacketrcv() claim a V1 or V2 ring slot before converting the virtio-net header. If the conversion fails, the drop path leaves the slot claimed.

With a one-frame TPACKETV2 ring, an unsupported UDP GSO packet leaves the only slot unavailable, so the ring also drops the next valid packet.

Clear the ownership bit on this error path. TPACKETV3 already clears its block state here.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In tpacket_rcv(), clear the RX ownership bit for the V1 or V2 ring slot when virtio-net header conversion fails, so the slot is not left claimed.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:38 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which packet-capture setups are affected?

The issue affects TPACKET_V2 packet rings that use virtio-net header conversion. The documented failure case requires a one-frame ring; TPACKET_V3 already clears its block state on this error path.

2

What traffic condition triggers the packet-loss behavior?

An unsupported UDP GSO packet must reach the affected TPACKET_V2 ring and fail virtio-net header conversion. That packet can leave the claimed ring slot unavailable, causing the next otherwise valid packet to be dropped when the ring has only one frame.

3

How can I identify a likely affected deployment?

Look for packet sockets using a one-frame TPACKET_V2 ring with virtio-net header processing, where an unsupported UDP GSO packet is followed by an unexpected drop of a valid packet. The observed behavior is loss of the next packet after the conversion error.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203