Out-of-bounds read in Linux kernel - CVE-2026-72351
Published: August 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in gue_remcsum() and gue_gro_remcsum() when processing malformed GUE packets with the REMCSUM private flag set but without the required REMCSUM metadata fields. A remote attacker can send a specially crafted packet to disclose sensitive information.
The issue occurs because option validation accepts packets that contain only the private flags field even when additional REMCSUM start and offset fields are expected.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)
How to mitigate CVE-2026-72351
linux (Ubuntu package) - addressed in versions 7.0.0-34.34, 7.0.0-34.34.1, 7.0.0-34.34~24.04.1, 7.0.0-1012.12~24.04.1, 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14, 7.0.0-1020.20
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14
External References
- https://git.kernel.org/stable/c/158b9995d3c87f3b93f5c22df54a12e12a3438b3
- https://git.kernel.org/stable/c/2a99224c120823987e4d829726f4ecb33e03fc1e
- https://git.kernel.org/stable/c/2c4de9988e9ddc760b750d6b6e701c35ff60ad14
- https://git.kernel.org/stable/c/4a4a1d41c6e901e773bcf795f562a47fa71f692a
- https://git.kernel.org/stable/c/61e78679c7c9ca685bff58e4b6348304dc60aafd
- https://git.kernel.org/stable/c/7c6876ec1b227261b51803f784c7be1b2242a1a0
- https://git.kernel.org/stable/c/d335dcc6f521571d57117b8deeebc940836e5450
- https://git.kernel.org/stable/c/f618cbe9b24cd0202004d2db781d5f80ab77037f