SB20260816501 - Incorrect calculation in Linux kernel netfilter ipvs



SB20260816501 - Incorrect calculation in Linux kernel netfilter ipvs

Published: August 16, 2026

Security Bulletin ID SB20260816501
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect calculation (CVE-ID: CVE-2026-72021)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect connection state tracking.

The vulnerability exists due to improper calculation of buffer offsets in SCTP state lookup in net/netfilter/ipvs/ip_vs_proto_sctp.c when processing IPv6 SCTP packets with extension headers. A remote attacker can send a specially crafted IPv6 SCTP packet with extension headers to cause incorrect connection state tracking.

This can cause an SCTP connection to be moved to the established state before the SCTP handshake has completed, resulting in incorrect timeout handling and destination counter updates.


Remediation

Install update from vendor's website.