SB2026091981 - Integer overflow in Linux kernel netfilter ipvs
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow (CVE-ID: CVE-2026-90141)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause the FTP helper to configure a data connection with a truncated port or address.
The vulnerability exists due to integer overflow in the ip_vs_ftp_get_addrport() function of the IPVS FTP helper when parsing a crafted FTP PASV or EPSV response. A remote attacker can send a crafted FTP PASV or EPSV response to cause the FTP helper to configure a data connection with a truncated port or address.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/00bcc6d679262ea42688fba1d7819ea6e56f12ef
- https://git.kernel.org/stable/c/4aed450adaee3a021db27be94c61fe025b0d05ff
- https://git.kernel.org/stable/c/50cb9b7263a2ed01f7d2f97818a800c2ee05f661
- https://git.kernel.org/stable/c/b1908bff0faaa94d55be72da65879cad632e8236
- https://git.kernel.org/stable/c/d02de9a7a7e2484da0cf37e50614840623b98a62
- https://git.kernel.org/stable/c/deaa88fa010ba0dfc554d09e006ddd1ce9945c82
- https://git.kernel.org/stable/c/e625a9477d12baaff4025c5f9989184a907ea8fc
- https://git.kernel.org/stable/c/fc1493c905d7e0bc8830c1d83915cb7831daf1a1