CVE-2026-98274

In the Linux kernel, the following vulnerability has been resolved: net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb() PSP conflicts with TLS ULP in its usage of both skb->decrypted and sk->sk_validate_xmit_skb(). Make PSP mutually exclusive with TLS ULP, the only other user of either of these. As other users of skb->decrypted come along, they can be added to sk_has_decrypt_user(). It would make sense to also assert that sk->sk_validate_xmit_skb() is also NULL in both of these setup paths for similar future proofing, but the PSP listener/sk_clone() path is still broken and it could be seen as a regression to not allow rx assoc to run on a child of a listener socket with PSP tx assoc state. Include all TCP ULPs in the sk_has_decrypt_user() check, even though TLS is the only one that conflicts with PSP via the decrypted bit. This is intentional because PSP was not designed to be used with ULPs. It is best to close off surface area that may make bugs reachable, until someone wishes to design and test an actual user of PSP with ULPs.

Package Linux Kernel
Published 2026-10-06
Last modified 2026-10-06
Patch available
Yes

Affected versions

Linux kernel versions 6.18 and later are affected. Fixed in 6.18.54, 7.2.8, 7.3-rc4 and their respective stable series.

Affected from
≥ 6.18
Fixed in
✓ 6.18.54 6.18.x ✓ 7.2.8 7.2.x ✓ 7.3-rc4

Frequently asked questions

  • What is CVE-2026-98274?

    CVE-2026-98274 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.18 onward and has been patched in 6.18.54, 7.2.8 and 7.3-rc4. CVE-2026-98274 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-98274?

    Yes. CVE-2026-98274 has been patched. Fixed versions include 6.18.54, 7.2.8 and 7.3-rc4. If you are running Linux kernel 6.18 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-98274 actively exploited?

    No. CVE-2026-98274 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.