SB20260816501 - Incorrect calculation in Linux kernel netfilter ipvs
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect calculation (CVE-ID: CVE-2026-72021)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect connection state tracking.
The vulnerability exists due to improper calculation of buffer offsets in SCTP state lookup in net/netfilter/ipvs/ip_vs_proto_sctp.c when processing IPv6 SCTP packets with extension headers. A remote attacker can send a specially crafted IPv6 SCTP packet with extension headers to cause incorrect connection state tracking.
This can cause an SCTP connection to be moved to the established state before the SCTP handshake has completed, resulting in incorrect timeout handling and destination counter updates.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/247d055504dcc852e539b9f7f30d19f9741474bf
- https://git.kernel.org/stable/c/290e9e8389b556efc603522e28bd1543846aa336
- https://git.kernel.org/stable/c/2f75c0faa3361b28e36cc0512b3299e163e25789
- https://git.kernel.org/stable/c/9cb5ac594ca76d3a71803b23b74c835b0721e628
- https://git.kernel.org/stable/c/9f94573ab962a9e81954b755da016fa3cd2f5039
- https://git.kernel.org/stable/c/a4a2d2e483d79cc2ad3a170674cf159644acf22b
- https://git.kernel.org/stable/c/d2b8b1557ec07ea1bb5dddbceaf4dfe63d388e27
- https://git.kernel.org/stable/c/e5d0bb8871668f20de8f3c94b5ae3f372346bc6e