CVE-2026-98105 Overview
CVE-2026-98105 affects the Linux kernel's oa_tc6 Ethernet driver, which implements the OPEN Alliance TC6 10BASE-T1x MAC-PHY serial interface. The driver fails to validate socket buffer (skb) tailroom before appending incoming data chunks. Under oversubscribed traffic conditions, buffer overflow errors cause data chunk loss, and the driver cannot locate a chunk with the end_valid bit set before exhausting sk_buff space. This triggers a kernel assertion inside skb_put.
Critical Impact
An assertion failure in skb_put within the oa_tc6 receive path can crash the kernel on affected systems when the Ethernet interface experiences sustained oversubscription or data chunk loss.
Affected Products
- Linux kernel versions containing the oa_tc6 Ethernet driver prior to the patched commits
- Embedded and IoT systems using OPEN Alliance TC6-compliant 10BASE-T1x MAC-PHY devices
- Stable kernel branches referenced in commits 172c974, 9d3f6e7, b89770d, and d33003e
Discovery Timeline
- 2026-09-25 - CVE-2026-98105 published to the National Vulnerability Database
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-98105
Vulnerability Analysis
The oa_tc6 driver reassembles Ethernet frames from fixed-size data chunks received over the MAC-PHY serial interface. Each chunk carries header bits including start_valid (SV) marking frame beginnings and end_valid (EV) marking frame terminations. The receive logic accumulates chunks into an sk_buff until a chunk with end_valid set signals the frame boundary.
When the link is oversubscribed, data chunks are lost. The driver can miss the chunk carrying end_valid, and continues appending subsequent chunks into the same sk_buff. Without a tailroom check, the append operation eventually exceeds the allocated buffer size. The kernel's skb_put helper detects the overflow and triggers an assertion, producing a BUG-class error in the networking stack.
Root Cause
The root cause is missing bounds validation before writing incoming chunk payloads into the destination sk_buff. The driver assumed frame boundaries would always be observed in order, treating only the rx_buf_overflow status bit as a recoverable condition. Allocation failures and invalid skb pointers were not routed through the same recovery path. The fix renames rx_buf_overflow to wait_until_start_valid to reflect its broader role in resynchronizing the receiver to the next start_valid chunk.
Attack Vector
The condition is reachable by any source capable of saturating the 10BASE-T1x link attached to a vulnerable interface. An attacker on the same physical segment can generate oversubscribed traffic that induces chunk loss, forcing the driver into the vulnerable code path. Successful triggering produces a kernel assertion that can disrupt the networking subsystem on the target host. The vulnerability does not provide a documented path to code execution; impact is denial of service against the affected kernel.
The patched driver validates skb_tailroom before each append, abandons the current frame when space is insufficient, and resumes parsing at the next chunk with start_valid set. sk_buff allocation failures are now treated as recoverable, and the driver no longer writes to status0 when it reads zero.
Detection Methods for CVE-2026-98105
Indicators of Compromise
- Kernel log entries containing skb_put assertion failures or skb_over_panic messages originating from the oa_tc6 module
- Repeated rx_buf_overflow status reports or interface resets on 10BASE-T1x MAC-PHY interfaces
- Networking stack hangs or BUG: traces referencing oa_tc6_rx functions in dmesg
Detection Strategies
- Monitor dmesg and /var/log/kern.log for assertion traces that reference the oa_tc6 driver and skb_put
- Correlate interface error counters (ethtool -S <iface>) with kernel log events to identify oversubscription-induced faults
- Track kernel version and loaded modules across embedded fleets to identify hosts running pre-patch builds of oa_tc6
Monitoring Recommendations
- Collect kernel ring buffer events to a centralized logging platform for pattern detection across devices
- Alert on sustained increases in receive buffer overflow counters on 10BASE-T1x interfaces
- Baseline the frequency of interface resets and investigate deviations that coincide with traffic bursts
How to Mitigate CVE-2026-98105
Immediate Actions Required
- Inventory all Linux systems using the oa_tc6 driver, including embedded controllers and IoT gateways with 10BASE-T1x MAC-PHY hardware
- Schedule updates to a kernel build that includes the fix commits 172c974, 9d3f6e7, b89770d, or d33003e
- Restrict physical and logical access to network segments carrying 10BASE-T1x traffic to reduce exposure to oversubscription conditions
Patch Information
The fix is distributed across four stable-tree commits: Linux Kernel Commit 172c97, Linux Kernel Commit 9d3f6e, Linux Kernel Commit b89770, and Linux Kernel Commit d33003. The patches add skb_tailroom validation before each chunk append, treat allocation failures as recoverable, rename rx_buf_overflow to wait_until_start_valid, and prevent writes to status0 when it reads zero.
Workarounds
- Rate-limit upstream traffic to the affected interface to avoid oversubscription on the 10BASE-T1x link
- Where possible, unload the oa_tc6 module on systems that do not require 10BASE-T1x connectivity
- Isolate affected interfaces on dedicated network segments to limit exposure to traffic bursts from untrusted sources
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.