SB20260816529 - Improper input validation in Linux kernel netfilter ipvs
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-68477)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect packet processing.
The vulnerability exists due to improper handling of ipv6 transport offsets in ipvs application and icmpv6 response processing when handling ipv6 packets with extension headers. A remote attacker can send specially crafted ipv6 traffic to cause incorrect packet processing.
The issue affects TCP application handling and ICMPv6 checksum validation in IPVS for IPv6 traffic.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3a9dc9b55b53d94613a587604b77d3b20024090c
- https://git.kernel.org/stable/c/613ce63711b8d431bba90781f133c39a21684f87
- https://git.kernel.org/stable/c/7350eb7ead172ae8024897d4b0f2e15c5318279c
- https://git.kernel.org/stable/c/905d7a363ade96a19f214815361e11981142c547
- https://git.kernel.org/stable/c/95d4511d81b2b37e5d2bdde5d912e48243eae517
- https://git.kernel.org/stable/c/a3f0d5b605cd5da5c95279969fb8cea4e55cee5b
- https://git.kernel.org/stable/c/b3fe4cbd583895987935a9bdad01c8f9d3a02310
- https://git.kernel.org/stable/c/d4ec18f48ce78a3bf7c999ac908691007375fe99