From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 73DC350EC14 for ; Fri, 4 Sep 2026 16:49:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788540542; cv=none; b=hFArQA6+r+TGQuGZqsEgItebTwpCRLxzWABVPYjU+qLEXCHn8liCKu1Fdy6mnVlQk71uqkqJedy8u0iWXxm2fEHhuoqr6wbKF54GDRBD13in1IGAR0xRF68kQBobiP4ktGcCItIp9pvztUWATntPz45yHKO7sl0JCuR6MuGykX8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788540542; c=relaxed/simple; bh=HqGRXE/35A/nEFCI0QcbH0tKsCMlyjtTLrJaXRYzRnQ=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=E+NQZ4LjHZte5OC5NnCUMKScXv1XalII3B31sM3MJ1+GtIxKcgHzb2iJLouimqSbTUPOAR27uvLbZVGvnMmqg+vw8y/1O7EAddvA7Yq85ukosg4uuKZoK5hoIdBPwxuwRV/equkKVWq+NfpKTy1rEcUm5DBmLtEbNTsAdwUAuh8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=aKNwjmvt; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="aKNwjmvt" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 171201F00A3D; Fri, 4 Sep 2026 16:48:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788540539; bh=A4hP+oAnjXY6muckvdH+WmJeM+nvyn43vmhTObBnRiA=; h=From:To:Cc:Subject:Date:Reply-To; b=aKNwjmvtJe16mkME0EKNx/hvwJiYPMKcvwPOYIKkpkAF7JkhfPcqTuGH8v/GzlHWR ZA6JWzXIK8MxWWK/7/1JUm78kYWdLgmKKyRdb/LJnN04hbZgAH4QSUxMyARNv4KOrh 3ALHTgBd00Y1H4y4Ie5rlDC64gb0o6Xe+PZ8BAgE= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80875: ipvs: use parsed transport offset in TCP state lookup Date: Fri, 4 Sep 2026 18:46:42 +0200 Message-ID: <2026090435-CVE-2026-80875-37f3@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3712; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=bXt/xEW0os1XbuMILRhSKp4nOdLOCnTW7g1ZPvVz5HY=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzvr6u+nnkpfG9Z8a1q02Nm1jY2cv0tDOP5wf/mjmvo u+9UNOpjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZhI2D6G2ey/XP69ahfPepEb v17gpKoBN0f+FIb51XEcy4/4pF+7I3KbT+XGklcSZdevAQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ipvs: use parsed transport offset in TCP state lookup TCP state handling reparses the skb to find the TCP header. For IPv6 it uses sizeof(struct ipv6hdr), while the surrounding IPVS code already parsed the packet with ip_vs_fill_iph_skb() and has the real transport-header offset in iph.len. This makes TCP state handling look at the wrong bytes when an IPv6 packet carries extension headers. Use the parsed transport offset passed down from ip_vs_set_state() when reading the TCP header. For IPv4 and for IPv6 packets without extension headers, the passed offset matches the previous value. The Linux kernel CVE team has assigned CVE-2026-80875 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 5.10.261 with commit 2d06e0897ce18228d199887f0823b431d841dd03 Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 5.15.212 with commit 816efb7fc0aeae986e63ac73b428dd97a4ef69f5 Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 6.1.178 with commit 5848e914b85e360a2dd9d19c00a72e2ea9617dd0 Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 6.6.145 with commit d45f73c274435703e8d7bc9d8b742a5d9111ab6e Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 6.12.97 with commit f6f550f26562d191c30b2818e7925dcb1c7f166c Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 6.18.40 with commit d73f4249776dd970ad65a69cfc51613dd8a034bb Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 7.1.5 with commit c2ee845e292c278fac75bf28d96bc892607fd5c4 Issue introduced in 2.6.28 with commit 0bbdd42b7efa66685b6d74701bcde3a596a3a59d and fixed in 7.2 with commit 2500fa3958b1ba51c2b065e39db1b04dfa7e23a2 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80875 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/netfilter/ipvs/ip_vs_proto_tcp.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/2d06e0897ce18228d199887f0823b431d841dd03 https://git.kernel.org/stable/c/816efb7fc0aeae986e63ac73b428dd97a4ef69f5 https://git.kernel.org/stable/c/5848e914b85e360a2dd9d19c00a72e2ea9617dd0 https://git.kernel.org/stable/c/d45f73c274435703e8d7bc9d8b742a5d9111ab6e https://git.kernel.org/stable/c/f6f550f26562d191c30b2818e7925dcb1c7f166c https://git.kernel.org/stable/c/d73f4249776dd970ad65a69cfc51613dd8a034bb https://git.kernel.org/stable/c/c2ee845e292c278fac75bf28d96bc892607fd5c4 https://git.kernel.org/stable/c/2500fa3958b1ba51c2b065e39db1b04dfa7e23a2