SB20260824122 - Stack-based buffer overflow in Linux kernel netfilter ipvs
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2026-74669)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a stack out-of-bounds write in ip_vs_in_icmp() when rebasing tunnel ICMP errors and processing IPv4 options. A remote attacker can send a specially crafted ICMP packet with IPv4 timestamp options to cause a denial of service.
The issue is triggered because stale IPv4 option metadata from the outer header is retained after the packet is rebased to the quoted original request.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/37c61b3745129cbd682c557b51345828120972e5
- https://git.kernel.org/stable/c/384b4dae14277d369221d187e9b3af56c79d2e50
- https://git.kernel.org/stable/c/6f46fc460e9316062bdcdf89199eb5d7a33da33b
- https://git.kernel.org/stable/c/75eec935444db4af2123e0491936f6e273d7ea00
- https://git.kernel.org/stable/c/79ffa99202c944467e28b13b513bf2998732edff
- https://git.kernel.org/stable/c/c9413b50204738fbc429bb86bf01353c393a6c28
- https://git.kernel.org/stable/c/e0ba936287dfe9783426aac27e5fd76fe35b38c9
- https://git.kernel.org/stable/c/ed246dd85ebf27c1f6b7897834d40786c0ca3006