Improper Validation of Array Index in Linux kernel - CVE-2026-97596
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to trigger an out-of-bounds transition table access.
The vulnerability exists due to improper validation of array indices in IPVS connection template synchronization record processing when processing a crafted IPVS synchronization record containing an invalid template state. A remote attacker can send a crafted IPVS synchronization record with an invalid template state to trigger an out-of-bounds transition table access.
The version 1 synchronization path handles both IPv4 and IPv6 records.