SB2026090551 - Improper input validation in Linux kernel netfilter ipvs
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-80901)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause IPVS to process ICMP messages with invalid checksums.
The vulnerability exists due to improper checksum validation in IPVS ICMP and ICMPv6 handling when processing ICMP messages. A remote attacker can send an ICMP message with an invalid checksum to cause IPVS to process ICMP messages with invalid checksums.
The issue includes ICMPv6 packets from clients and ICMPv6 responses from real servers when checksum validation is not performed by hardware.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/00eb23829fd08df1b5e057cb6b625996a70e7e65
- https://git.kernel.org/stable/c/5558a85add073215b298f3e044ff9a6d86d714ae
- https://git.kernel.org/stable/c/9cbe2c0fdb71904ee929b1851cdc1c73341a03c0
- https://git.kernel.org/stable/c/b3869d9b54e76dff64118dee4c8fd9302fcd5171
- https://git.kernel.org/stable/c/d418d73acf8be62744dc47359dfdde8c2148845d
- https://git.kernel.org/stable/c/e876b75b9020a97bbdc79721e7fc749024891c65