Improper input validation in Linux kernel - CVE-2026-80901

 

Improper input validation in Linux kernel - CVE-2026-80901

Published: September 5, 2026


Vulnerability identifier: #VU147020
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80901
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause IPVS to process ICMP messages with invalid checksums.

The vulnerability exists due to improper checksum validation in IPVS ICMP and ICMPv6 handling when processing ICMP messages. A remote attacker can send an ICMP message with an invalid checksum to cause IPVS to process ICMP messages with invalid checksums.

The issue includes ICMPv6 packets from clients and ICMPv6 responses from real servers when checksum validation is not performed by hardware.


Affected software

Linux kernel

How to mitigate CVE-2026-80901

Install security update from vendor's repository.


External References

Related Security Bulletins