Improper input validation in Linux kernel - CVE-2026-80901
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause IPVS to process ICMP messages with invalid checksums.
The vulnerability exists due to improper checksum validation in IPVS ICMP and ICMPv6 handling when processing ICMP messages. A remote attacker can send an ICMP message with an invalid checksum to cause IPVS to process ICMP messages with invalid checksums.
The issue includes ICMPv6 packets from clients and ICMPv6 responses from real servers when checksum validation is not performed by hardware.
Affected software
How to mitigate CVE-2026-80901
External References
- https://git.kernel.org/stable/c/00eb23829fd08df1b5e057cb6b625996a70e7e65
- https://git.kernel.org/stable/c/5558a85add073215b298f3e044ff9a6d86d714ae
- https://git.kernel.org/stable/c/9cbe2c0fdb71904ee929b1851cdc1c73341a03c0
- https://git.kernel.org/stable/c/b3869d9b54e76dff64118dee4c8fd9302fcd5171
- https://git.kernel.org/stable/c/d418d73acf8be62744dc47359dfdde8c2148845d
- https://git.kernel.org/stable/c/e876b75b9020a97bbdc79721e7fc749024891c65