CVE-2026-98240: net: ip_tunnel: initialize `options_len` before referencing options

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: iptunnel: initialize optionslen before referencing options

The following command triggers a kernel panic:

ip link add d0 type dummy; ip link set d0 up ip route add 10.30.0.0/16 \ encap ip id 300 geneveopts 4660:66:11223344 dev d0

memcpy: detected buffer overflow: 4 byte write of buffer size 0 kernel BUG at lib/stringhelpers.c:1044! ... iptunparseopts.part.0.cold+0x10/0x10 iptunbuildstate+0x116/0x2a0

On kernels built with GCC 15+ and CONFIGFORTIFYSOURCE, the fortified memcpy() got 0 sized destination with request of 4 bytes length:

static int iptunparseoptsgeneve(...) { ... attr = tb[LWTUNNELIPOPTGENEVEDATA]; datalen = nlalen(attr); / == 4 /

struct geneveopt opt = iptunnelinfoopts(info) + optslen; memcpy(opt->optdata, nladata(attr), datalen); / ^^^^^^^^^^^^^ 0 since optionslen is assigned afterwards /

Fixed by initializing the counter before the options are referenced. Matching what tunnelkeyoptsset() already does.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 6, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
Description
Data Sourced
via NVD·09:18 AM
Description

Frequently Asked Questions

1

Which systems are most directly exposed to the reported panic?

The report specifically identifies kernels built with GCC 15 or later with CONFIG_FORTIFY_SOURCE enabled. In that configuration, the fortified memcpy detects the zero-sized destination and triggers a kernel BUG.

2

What network configuration action triggers the issue?

The provided reproducer creates and enables a dummy interface, then adds an IP route using IP encapsulation with Geneve options. The Geneve option data causes a 4-byte copy into storage whose effective size is zero before options_len is initialized.

3

What is the operational impact of exploitation?

The demonstrated outcome is a kernel panic caused by a detected buffer overflow, resulting in a denial of service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203