SB2026081624 - Improper input validation in Linux kernel ipv6 netfilter



SB2026081624 - Improper input validation in Linux kernel ipv6 netfilter

Published: August 16, 2026

Security Bulletin ID SB2026081624
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper input validation (CVE-ID: CVE-2026-72348)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass packet-filtering rules.

The vulnerability exists due to improper input validation in the ip6tables ah, hbh, and rt IPv6 extension header match handlers when processing malformed IPv6 packets with advertised extension header lengths that exceed the available skb data. A remote attacker can send a specially crafted IPv6 packet to bypass packet-filtering rules.

The issue affects handling of malformed IPv6 authentication, hop-by-hop, and routing extension headers.


Remediation

Install update from vendor's website.