-

CVE-2026-98299

tcp: do not let tcp_rmem be set below 4096

In the Linux kernel, the following vulnerability has been resolved:

tcp: do not let tcp_rmem be set below 4096

We can hit a division by zero crash in tcp_rcvbuf_grow()
and tcp_rcv_space_adjust():

divide error: 0000 [#1] PREEMPT SMP
RIP: 0010:tcp_rcvbuf_grow+0x187/0x450 net/ipv4/tcp_input.c:939
...
grow = div_u64(((u64)rcvwin << 1) * (newval - oldval), oldval);

The division uses oldval = tp->rcvq_space.space as divisor.
When tp->rcvq_space.space is zero, this leads to a divide-by-zero
exception.

tp->rcvq_space.space is initialized in tcp_init_buffer_space():
    tp->rcvq_space.space = min3(tp->rcv_ssthresh, tp->rcv_wnd,
                                (u32)TCP_INIT_CWND * tp->advmss);

If tcp_rmem[1] is configured to very small values (such as 1),
sk->sk_rcvbuf is initialized to 1. Then tcp_full_space(sk), which
computes (sk->sk_rcvbuf * scaling_ratio) >> 8, truncates to 0.
This sets tp->window_clamp = 0, tp->rcv_ssthresh = 0, and
tp->rcvq_space.space = 0. Later, when data arrives and DRS is invoked,
tcp_rcvbuf_grow() divides by oldval == 0.

Back in 2015, commit b1cb59cf2efe ("net: sysctl_net_core: check SNDBUF
and RCVBUF for min length") ensured that net.core.rmem_default and
net.core.rmem_max cannot be set below SOCK_MIN_RCVBUF. Similarly,
SO_RCVBUF setsockopt enforces max_t(int, val * 2, SOCK_MIN_RCVBUF).

However, net.ipv4.tcp_rmem still had .extra1 = SYSCTL_ONE, allowing
arbitrarily small values.

Because SOCK_MIN_RCVBUF depends on sizeof(struct sk_buff) and cacheline
alignment, its value varies across architectures and configuration options.
Using a fixed constant of 4096 ensures a predictable, architecture-
independent lower bound that is safely above SOCK_MIN_RCVBUF everywhere
and matches the documented 4K default.

Fix this by setting tcp_rmem.extra1 to 4096 and updating the documentation.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 879907631b9e70eedb62d76461b29afa106ebe7a
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 8e32532d0fa3191ecf9524b0e6bafa0832e712ba
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 67b83c15bed9eeeb8d1a6dbf88a5f79525970173
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 9a4f49bf8d2da4e52e904f60c29cca317bab9b3a
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 60df201dbb19a1bf6478b56d100f7ae1fe90e46a
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 7898bda1ebc198f5559b301a96dd5398edd4d4d3
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 1c4bb940c3bb4325bb88ac1b7eaf5faaa39e7d63
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 83a945a529d6e002dd7339c532288a931f463dba
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.073
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/879907631b9e70eedb62d76461b29afa106ebe7a
https://git.kernel.org/stable/c/8e32532d0fa3191ecf9524b0e6bafa0832e712ba
https://git.kernel.org/stable/c/67b83c15bed9eeeb8d1a6dbf88a5f79525970173
https://git.kernel.org/stable/c/9a4f49bf8d2da4e52e904f60c29cca317bab9b3a
https://git.kernel.org/stable/c/60df201dbb19a1bf6478b56d100f7ae1fe90e46a
https://git.kernel.org/stable/c/7898bda1ebc198f5559b301a96dd5398edd4d4d3
https://git.kernel.org/stable/c/1c4bb940c3bb4325bb88ac1b7eaf5faaa39e7d63
https://git.kernel.org/stable/c/83a945a529d6e002dd7339c532288a931f463dba