Description
In the Linux kernel, the following vulnerability has been resolved:

net/packet: clear RX owner on VNET header error

Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race
condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2
ring slot before converting the virtio-net header. If the conversion
fails, the drop path leaves the slot claimed.

With a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves
the only slot unavailable, so the ring also drops the next valid packet.

Clear the ownership bit on this error path. TPACKET_V3 already clears
its block state here.
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Kernel
AI Analysis

Impact

An improper handling of the virtual‑network packet ring causes a race condition that can leave a ring slot claimed after a failed header conversion. When a single‑frame TPACKET_V2 ring receives an unsupported UDP GSO packet, the only slot remains unavailable and the next valid packet is dropped, resulting in loss of traffic. The flaw does not disclose data or provide privilege escalation, but it can disrupt normal network operation by dropping legitimate packets and potentially blocking service if the loss is severe.

Affected Systems

The affected component is the Linux kernel’s networking packet receive path (tpacket_rcv). The issue exists in kernels that support a V1 or V2 ring slot map before conversion of virtio‑net headers. The patch fixing the bug (commit 61fad6816fc1) has been incorporated in later kernel releases; any earlier kernel version that includes this commit chain remains vulnerable.

Risk and Exploitability

Exploitability is not quantified by EPSS and the vulnerability is not listed in CISA’s KEV catalog, indicating a lack of widely available public exploits. An attacker could trigger the race condition by sending specially crafted UDP GSO packets into a host using a single‑frame TPACKET_V2 ring, leading to packet loss and a potential denial of service to applications relying on those packets. The likelihood of random failure is low, but an adversary who can inject traffic to the target can reliably exploit the flaw.

Generated by OpenCVE AI on October 6, 2026 at 11:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes commit 61fad6816fc1 or later to remove the race condition
  • Upgrade to the most recent stable kernel release available for the distribution to ensure the patch is present
  • If patching is delayed, disable or limit the use of TPACKET_V2 ring sockets and avoid sending UDP GSO packets on affected systems to reduce the risk of packet loss

Generated by OpenCVE AI on October 6, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/packet: clear RX owner on VNET header error Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2 ring slot before converting the virtio-net header. If the conversion fails, the drop path leaves the slot claimed. With a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves the only slot unavailable, so the ring also drops the next valid packet. Clear the ownership bit on this error path. TPACKET_V3 already clears its block state here.
Title net/packet: clear RX owner on VNET header error
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-06T08:45:06.533Z

Reserved: 2026-09-25T10:25:14.328Z

Link: CVE-2026-98233

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:18:10.857

Modified: 2026-10-06T09:18:10.857

Link: CVE-2026-98233

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T12:00:15Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')