SB2026090551 - Improper input validation in Linux kernel netfilter ipvs



SB2026090551 - Improper input validation in Linux kernel netfilter ipvs

Published: September 5, 2026

Security Bulletin ID SB2026090551
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper input validation (CVE-ID: CVE-2026-80901)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause IPVS to process ICMP messages with invalid checksums.

The vulnerability exists due to improper checksum validation in IPVS ICMP and ICMPv6 handling when processing ICMP messages. A remote attacker can send an ICMP message with an invalid checksum to cause IPVS to process ICMP messages with invalid checksums.

The issue includes ICMPv6 packets from clients and ICMPv6 responses from real servers when checksum validation is not performed by hardware.


Remediation

Install update from vendor's website.