Integer overflow in Linux kernel - CVE-2026-90141
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause the FTP helper to configure a data connection with a truncated port or address.
The vulnerability exists due to integer overflow in the ip_vs_ftp_get_addrport() function of the IPVS FTP helper when parsing a crafted FTP PASV or EPSV response. A remote attacker can send a crafted FTP PASV or EPSV response to cause the FTP helper to configure a data connection with a truncated port or address.
Affected software
How to mitigate CVE-2026-90141
External References
- https://git.kernel.org/stable/c/00bcc6d679262ea42688fba1d7819ea6e56f12ef
- https://git.kernel.org/stable/c/4aed450adaee3a021db27be94c61fe025b0d05ff
- https://git.kernel.org/stable/c/50cb9b7263a2ed01f7d2f97818a800c2ee05f661
- https://git.kernel.org/stable/c/b1908bff0faaa94d55be72da65879cad632e8236
- https://git.kernel.org/stable/c/d02de9a7a7e2484da0cf37e50614840623b98a62
- https://git.kernel.org/stable/c/deaa88fa010ba0dfc554d09e006ddd1ce9945c82
- https://git.kernel.org/stable/c/e625a9477d12baaff4025c5f9989184a907ea8fc
- https://git.kernel.org/stable/c/fc1493c905d7e0bc8830c1d83915cb7831daf1a1