{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  tcp: do not let tcp_rmem be set below 4096  We can hit a division by zero crash in tcp_rcvbuf_grow() and tcp_rcv_space_adjust():  divide error: 0000 [#1] PREEMPT SMP RIP: 0010:tcp_rcvbuf_grow+0x187/0x450 net/ipv4/tcp_input.c:939 ... grow = div_u64(((u64)rcvwin \u003c\u003c 1) * (newval - oldval), oldval);  The division uses oldval = tp-\u003ercvq_space.space as divisor. When tp-\u003ercvq_space.space is zero, this leads to a divide-by-zero exception.  tp-\u003ercvq_space.space is initialized in tcp_init_buffer_space():     tp-\u003ercvq_space.space = min3(tp-\u003ercv_ssthresh, tp-\u003ercv_wnd,                                 (u32)TCP_INIT_CWND * tp-\u003eadvmss);  If tcp_rmem[1] is configured to very small values (such as 1), sk-\u003esk_rcvbuf is initialized to 1. Then tcp_full_space(sk), which computes (sk-\u003esk_rcvbuf * scaling_ratio) \u003e\u003e 8, truncates to 0. This sets tp-\u003ewindow_clamp = 0, tp-\u003ercv_ssthresh = 0, and tp-\u003ercvq_space.space = 0. Later, when data arrives and DRS is invoked, tcp_rcvbuf_grow() divides by oldval == 0.  Back in 2015, commit b1cb59cf2efe (\"net: sysctl_net_core: check SNDBUF and RCVBUF for min length\") ensured that net.core.rmem_default and net.core.rmem_max cannot be set below SOCK_MIN_RCVBUF. Similarly, SO_RCVBUF setsockopt enforces max_t(int, val * 2, SOCK_MIN_RCVBUF).  However, net.ipv4.tcp_rmem still had .extra1 = SYSCTL_ONE, allowing arbitrarily small values.  Because SOCK_MIN_RCVBUF depends on sizeof(struct sk_buff) and cacheline alignment, its value varies across architectures and configuration options. Using a fixed constant of 4096 ensures a predictable, architecture- independent lower bound that is safely above SOCK_MIN_RCVBUF everywhere and matches the documented 4K default.  Fix this by setting tcp_rmem.extra1 to 4096 and updating the documentation.",
  "id": "DEBIAN-CVE-2026-98299",
  "modified": "2026-10-07T04:47:30.038771312Z",
  "published": "2026-10-06T09:18:20.697Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98299"
    }
  ],
  "upstream": [
    "CVE-2026-98299"
  ]
}