Skip to main content
Vulnerability Database/CVE-2026-98105

CVE-2026-98105: Linux Kernel Buffer Overflow Vulnerability

CVE-2026-98105 is a buffer overflow flaw in the Linux kernel oa_tc6 ethernet driver that causes errors during oversubscribed traffic. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-98105 Overview

CVE-2026-98105 affects the Linux kernel's oa_tc6 Ethernet driver, which implements the OPEN Alliance TC6 10BASE-T1x MAC-PHY serial interface. The driver fails to validate socket buffer (skb) tailroom before appending incoming data chunks. Under oversubscribed traffic conditions, buffer overflow errors cause data chunk loss, and the driver cannot locate a chunk with the end_valid bit set before exhausting sk_buff space. This triggers a kernel assertion inside skb_put.

Critical Impact

An assertion failure in skb_put within the oa_tc6 receive path can crash the kernel on affected systems when the Ethernet interface experiences sustained oversubscription or data chunk loss.

Affected Products

  • Linux kernel versions containing the oa_tc6 Ethernet driver prior to the patched commits
  • Embedded and IoT systems using OPEN Alliance TC6-compliant 10BASE-T1x MAC-PHY devices
  • Stable kernel branches referenced in commits 172c974, 9d3f6e7, b89770d, and d33003e

Discovery Timeline

  • 2026-09-25 - CVE-2026-98105 published to the National Vulnerability Database
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-98105

Vulnerability Analysis

The oa_tc6 driver reassembles Ethernet frames from fixed-size data chunks received over the MAC-PHY serial interface. Each chunk carries header bits including start_valid (SV) marking frame beginnings and end_valid (EV) marking frame terminations. The receive logic accumulates chunks into an sk_buff until a chunk with end_valid set signals the frame boundary.

When the link is oversubscribed, data chunks are lost. The driver can miss the chunk carrying end_valid, and continues appending subsequent chunks into the same sk_buff. Without a tailroom check, the append operation eventually exceeds the allocated buffer size. The kernel's skb_put helper detects the overflow and triggers an assertion, producing a BUG-class error in the networking stack.

Root Cause

The root cause is missing bounds validation before writing incoming chunk payloads into the destination sk_buff. The driver assumed frame boundaries would always be observed in order, treating only the rx_buf_overflow status bit as a recoverable condition. Allocation failures and invalid skb pointers were not routed through the same recovery path. The fix renames rx_buf_overflow to wait_until_start_valid to reflect its broader role in resynchronizing the receiver to the next start_valid chunk.

Attack Vector

The condition is reachable by any source capable of saturating the 10BASE-T1x link attached to a vulnerable interface. An attacker on the same physical segment can generate oversubscribed traffic that induces chunk loss, forcing the driver into the vulnerable code path. Successful triggering produces a kernel assertion that can disrupt the networking subsystem on the target host. The vulnerability does not provide a documented path to code execution; impact is denial of service against the affected kernel.

The patched driver validates skb_tailroom before each append, abandons the current frame when space is insufficient, and resumes parsing at the next chunk with start_valid set. sk_buff allocation failures are now treated as recoverable, and the driver no longer writes to status0 when it reads zero.

Detection Methods for CVE-2026-98105

Indicators of Compromise

  • Kernel log entries containing skb_put assertion failures or skb_over_panic messages originating from the oa_tc6 module
  • Repeated rx_buf_overflow status reports or interface resets on 10BASE-T1x MAC-PHY interfaces
  • Networking stack hangs or BUG: traces referencing oa_tc6_rx functions in dmesg

Detection Strategies

  • Monitor dmesg and /var/log/kern.log for assertion traces that reference the oa_tc6 driver and skb_put
  • Correlate interface error counters (ethtool -S <iface>) with kernel log events to identify oversubscription-induced faults
  • Track kernel version and loaded modules across embedded fleets to identify hosts running pre-patch builds of oa_tc6

Monitoring Recommendations

  • Collect kernel ring buffer events to a centralized logging platform for pattern detection across devices
  • Alert on sustained increases in receive buffer overflow counters on 10BASE-T1x interfaces
  • Baseline the frequency of interface resets and investigate deviations that coincide with traffic bursts

How to Mitigate CVE-2026-98105

Immediate Actions Required

  • Inventory all Linux systems using the oa_tc6 driver, including embedded controllers and IoT gateways with 10BASE-T1x MAC-PHY hardware
  • Schedule updates to a kernel build that includes the fix commits 172c974, 9d3f6e7, b89770d, or d33003e
  • Restrict physical and logical access to network segments carrying 10BASE-T1x traffic to reduce exposure to oversubscription conditions

Patch Information

The fix is distributed across four stable-tree commits: Linux Kernel Commit 172c97, Linux Kernel Commit 9d3f6e, Linux Kernel Commit b89770, and Linux Kernel Commit d33003. The patches add skb_tailroom validation before each chunk append, treat allocation failures as recoverable, rename rx_buf_overflow to wait_until_start_valid, and prevent writes to status0 when it reads zero.

Workarounds

  • Rate-limit upstream traffic to the affected interface to avoid oversubscription on the 10BASE-T1x link
  • Where possible, unload the oa_tc6 module on systems that do not require 10BASE-T1x connectivity
  • Isolate affected interfaces on dedicated network segments to limit exposure to traffic bursts from untrusted sources

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.