Incorrect calculation in Linux kernel - CVE-2026-80875
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause incorrect TCP state handling.
The vulnerability exists due to an incorrect transport-header offset calculation in the IPVS TCP state lookup when processing IPv6 packets with extension headers. A remote attacker can send a crafted IPv6 packet with extension headers to cause incorrect TCP state handling.
Affected software
How to mitigate CVE-2026-80875
External References
- https://git.kernel.org/stable/c/2500fa3958b1ba51c2b065e39db1b04dfa7e23a2
- https://git.kernel.org/stable/c/2d06e0897ce18228d199887f0823b431d841dd03
- https://git.kernel.org/stable/c/5848e914b85e360a2dd9d19c00a72e2ea9617dd0
- https://git.kernel.org/stable/c/816efb7fc0aeae986e63ac73b428dd97a4ef69f5
- https://git.kernel.org/stable/c/c2ee845e292c278fac75bf28d96bc892607fd5c4
- https://git.kernel.org/stable/c/d45f73c274435703e8d7bc9d8b742a5d9111ab6e
- https://git.kernel.org/stable/c/d73f4249776dd970ad65a69cfc51613dd8a034bb
- https://git.kernel.org/stable/c/f6f550f26562d191c30b2818e7925dcb1c7f166c