SB20260816517 - Use of Uninitialized Variable in Linux kernel netfilter ipvs
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of Uninitialized Variable (CVE-ID: CVE-2026-72020)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information and corrupt forwarded TCP traffic.
The vulnerability exists due to use of uninitialized memory in ip_vs_conn_new and TCP sequence handling in IPVS when processing a malformed sync message that omits sequence data. A remote user can send a specially crafted sync message to disclose sensitive information and corrupt forwarded TCP traffic.
The issue affects connections learned from a sync message when sequence flags are preserved without valid sequence data, causing stale slab bytes to be used in TCP sequence and acknowledgment number rewriting by an IPVS application helper.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2975324d164c552b028632f107b567302863b7f6
- https://git.kernel.org/stable/c/32c299e28b8eea6cbbd23b97dc61401e9ef9c445
- https://git.kernel.org/stable/c/3bf9a260188b2a5449cbddc032a749ab433fe328
- https://git.kernel.org/stable/c/6335ab62d5fc9ed875279238233fba3462c168f5
- https://git.kernel.org/stable/c/6378c5cb360eb1750f88839d7c3613ea92ac1816
- https://git.kernel.org/stable/c/83fb4c2c5344f02eac929f66de3c9d1adfcde04c
- https://git.kernel.org/stable/c/9e36602cbec552286f7e691cfd366525c565ee74
- https://git.kernel.org/stable/c/d0eed7177e822cab83141e5c44b2aa345c7fd379