SB2026081665 - Improper input validation in Linux kernel netfilter ipvs
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-72319)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ip_vs_in_icmp in the IPVS subsystem when processing ICMP error packets from tunnels. A remote attacker can send a specially crafted ICMP error packet to cause a denial of service.
The issue involves inner IP headers not being ensured in skb headroom after outer headers are stripped, and additional length checks were required for the inner headers.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/19657b3a17b774ae4e2f2635b5ae8638c9344a40
- https://git.kernel.org/stable/c/3f7a535ff0fa627a0132803e4c2f903ceffcbc1c
- https://git.kernel.org/stable/c/8f48cfe657409fb5c7ba0521b14da6d47546d9cf
- https://git.kernel.org/stable/c/92185d6f7819bc558939ae83de7b1abe90e3b5c2
- https://git.kernel.org/stable/c/9bc9b95aee2b2e3f1301a16a67ee504960402875
- https://git.kernel.org/stable/c/a735f9964a3d9ed97daf9b08507f8b5bcafe6326
- https://git.kernel.org/stable/c/dac813101914c21219ac221a60a31a11bc90e7ec
- https://git.kernel.org/stable/c/dd22f74a09e25ca298ced0a3763ef353242cb78d