{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "bb5e62f2d547c4de6d1b144cbce2373a76c33f18"
            },
            {
              "fixed": "9907325257b4b382f26aafd5d9a8d47915907dd5"
            },
            {
              "fixed": "0f6a6beb01c068fcd5274eabf22c260039749fea"
            },
            {
              "fixed": "455ebeadf714f51e1dbbd6a022c74c9215b1cd76"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.15.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98240.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip_tunnel: initialize `options_len` before referencing options\n\nThe following command triggers a kernel panic:\n\n  ip link add d0 type dummy; ip link set d0 up\n  ip route add 10.30.0.0/16 \\\n    encap ip id 300 geneve_opts 4660:66:11223344 dev d0\n\n  memcpy: detected buffer overflow: 4 byte write of buffer size 0\n  kernel BUG at lib/string_helpers.c:1044!\n  ...\n  ip_tun_parse_opts.part.0.cold+0x10/0x10\n  ip_tun_build_state+0x116/0x2a0\n\nOn kernels built with GCC 15+ and `CONFIG_FORTIFY_SOURCE`, the fortified\n`memcpy()` got 0 sized destination with request of 4 bytes length:\n\n  static int ip_tun_parse_opts_geneve(...)\n  {\n      ...\n      attr = tb[LWTUNNEL_IP_OPT_GENEVE_DATA];\n      data_len = nla_len(attr); /* == 4 */\n\n      struct geneve_opt *opt = ip_tunnel_info_opts(info) + opts_len;\n      memcpy(opt-\u003eopt_data, nla_data(attr), data_len);\n      /*     ^^^^^^^^^^^^^ 0 since options_len is assigned afterwards */\n\nFixed by initializing the counter before the options are referenced.\nMatching what `tunnel_key_opts_set()` already does.",
  "id": "CVE-2026-98240",
  "modified": "2026-10-08T02:30:39.635979336Z",
  "published": "2026-10-06T08:45:11.284Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0f6a6beb01c068fcd5274eabf22c260039749fea"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/455ebeadf714f51e1dbbd6a022c74c9215b1cd76"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/9907325257b4b382f26aafd5d9a8d47915907dd5"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98240.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98240"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "net: ip_tunnel: initialize `options_len` before referencing options"
}