CVE-2026-98240: net: ip_tunnel: initialize `options_len` before referencing options
In the Linux kernel, the following vulnerability has been resolved:
net: iptunnel: initialize optionslen before referencing options
The following command triggers a kernel panic:
ip link add d0 type dummy; ip link set d0 up ip route add 10.30.0.0/16 \ encap ip id 300 geneveopts 4660:66:11223344 dev d0
memcpy: detected buffer overflow: 4 byte write of buffer size 0 kernel BUG at lib/stringhelpers.c:1044! ... iptunparseopts.part.0.cold+0x10/0x10 iptunbuildstate+0x116/0x2a0
On kernels built with GCC 15+ and CONFIGFORTIFYSOURCE, the fortified memcpy() got 0 sized destination with request of 4 bytes length:
static int iptunparseoptsgeneve(...) { ... attr = tb[LWTUNNELIPOPTGENEVEDATA]; datalen = nlalen(attr); / == 4 /
struct geneveopt opt = iptunnelinfoopts(info) + optslen; memcpy(opt->optdata, nladata(attr), datalen); / ^^^^^^^^^^^^^ 0 since optionslen is assigned afterwards /
Fixed by initializing the counter before the options are referenced. Matching what tunnelkeyoptsset() already does.
Affected Software
Event History
Frequently Asked Questions
Which systems are most directly exposed to the reported panic?
The report specifically identifies kernels built with GCC 15 or later with CONFIG_FORTIFY_SOURCE enabled. In that configuration, the fortified memcpy detects the zero-sized destination and triggers a kernel BUG.
What network configuration action triggers the issue?
The provided reproducer creates and enables a dummy interface, then adds an IP route using IP encapsulation with Geneve options. The Geneve option data causes a 4-byte copy into storage whose effective size is zero before options_len is initialized.
What is the operational impact of exploitation?
The demonstrated outcome is a kernel panic caused by a detected buffer overflow, resulting in a denial of service.