* CVE-2026-80875: ipvs: use parsed transport offset in TCP state lookup
@ 2026-09-04 16:46 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 16:46 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
ipvs: use parsed transport offset in TCP state lookup
TCP state handling reparses the skb to find the TCP header. For IPv6 it
uses sizeof(struct ipv6hdr), while the surrounding IPVS code already
parsed the packet with ip_vs_fill_iph_skb() and has the real
transport-header offset in iph.len.
This makes TCP state handling look at the wrong bytes when an IPv6
packet carries extension headers. Use the parsed transport offset passed
down from ip_vs_set_state() when reading the TCP header.
For IPv4 and for IPv6 packets without extension headers, the passed
offset matches the previous value.
The Linux kernel CVE team has assigned CVE-2026-80875 to this issue.
Affected and fixed versions
===========================
Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 5.10.261 with commit 2d06e0897ce18228d199887f0823b431d841dd03
Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 5.15.212 with commit 816efb7fc0aeae986e63ac73b428dd97a4ef69f5
Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 6.1.178 with commit 5848e914b85e360a2dd9d19c00a72e2ea9617dd0
Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 6.6.145 with commit d45f73c274435703e8d7bc9d8b742a5d9111ab6e
Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 6.12.97 with commit f6f550f26562d191c30b2818e7925dcb1c7f166c
Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 6.18.40 with commit d73f4249776dd970ad65a69cfc51613dd8a034bb
Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 7.1.5 with commit c2ee845e292c278fac75bf28d96bc892607fd5c4
Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 7.2 with commit 2500fa3958b1ba51c2b065e39db1b04dfa7e23a2
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-80875
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
net/netfilter/ipvs/ip_vs_proto_tcp.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/2d06e0897ce18228d199887f0823b431d841dd03
https://git.kernel.org/stable/c/816efb7fc0aeae986e63ac73b428dd97a4ef69f5
https://git.kernel.org/stable/c/5848e914b85e360a2dd9d19c00a72e2ea9617dd0
https://git.kernel.org/stable/c/d45f73c274435703e8d7bc9d8b742a5d9111ab6e
https://git.kernel.org/stable/c/f6f550f26562d191c30b2818e7925dcb1c7f166c
https://git.kernel.org/stable/c/d73f4249776dd970ad65a69cfc51613dd8a034bb
https://git.kernel.org/stable/c/c2ee845e292c278fac75bf28d96bc892607fd5c4
https://git.kernel.org/stable/c/2500fa3958b1ba51c2b065e39db1b04dfa7e23a2
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-04 16:49 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 16:46 CVE-2026-80875: ipvs: use parsed transport offset in TCP state lookup Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.