Improper input validation in Linux kernel - CVE-2026-72348

 

Improper input validation in Linux kernel - CVE-2026-72348

Published: August 16, 2026


Vulnerability identifier: #VU143086
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72348
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass packet-filtering rules.

The vulnerability exists due to improper input validation in the ip6tables ah, hbh, and rt IPv6 extension header match handlers when processing malformed IPv6 packets with advertised extension header lengths that exceed the available skb data. A remote attacker can send a specially crafted IPv6 packet to bypass packet-filtering rules.

The issue affects handling of malformed IPv6 authentication, hop-by-hop, and routing extension headers.


Affected software

Linux kernel
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)

How to mitigate CVE-2026-72348

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 7.0.0-34.34, 7.0.0-34.34.1, 7.0.0-34.34~24.04.1, 7.0.0-1012.12~24.04.1, 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14, 7.0.0-1020.20
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14

External References

Related Security Bulletins