{"id":"CVE-2026-98240","summary":"net: ip_tunnel: initialize `options_len` before referencing options","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip_tunnel: initialize `options_len` before referencing options\n\nThe following command triggers a kernel panic:\n\n  ip link add d0 type dummy; ip link set d0 up\n  ip route add 10.30.0.0/16 \\\n    encap ip id 300 geneve_opts 4660:66:11223344 dev d0\n\n  memcpy: detected buffer overflow: 4 byte write of buffer size 0\n  kernel BUG at lib/string_helpers.c:1044!\n  ...\n  ip_tun_parse_opts.part.0.cold+0x10/0x10\n  ip_tun_build_state+0x116/0x2a0\n\nOn kernels built with GCC 15+ and `CONFIG_FORTIFY_SOURCE`, the fortified\n`memcpy()` got 0 sized destination with request of 4 bytes length:\n\n  static int ip_tun_parse_opts_geneve(...)\n  {\n      ...\n      attr = tb[LWTUNNEL_IP_OPT_GENEVE_DATA];\n      data_len = nla_len(attr); /* == 4 */\n\n      struct geneve_opt *opt = ip_tunnel_info_opts(info) + opts_len;\n      memcpy(opt-\u003eopt_data, nla_data(attr), data_len);\n      /*     ^^^^^^^^^^^^^ 0 since options_len is assigned afterwards */\n\nFixed by initializing the counter before the options are referenced.\nMatching what `tunnel_key_opts_set()` already does.","modified":"2026-10-08T02:52:54.832747314Z","published":"2026-10-06T08:45:11.284Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98240.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0f6a6beb01c068fcd5274eabf22c260039749fea"},{"type":"WEB","url":"https://git.kernel.org/stable/c/455ebeadf714f51e1dbbd6a022c74c9215b1cd76"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9907325257b4b382f26aafd5d9a8d47915907dd5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98240.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98240"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"bb5e62f2d547c4de6d1b144cbce2373a76c33f18"},{"fixed":"9907325257b4b382f26aafd5d9a8d47915907dd5"},{"fixed":"0f6a6beb01c068fcd5274eabf22c260039749fea"},{"fixed":"455ebeadf714f51e1dbbd6a022c74c9215b1cd76"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98240.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.15.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98240.json"}}],"schema_version":"1.9.0"}