CVE-2026-72417

Summary

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()

Add sanity check for iph->ihl field in nf_flow_ip4_tunnel_proto() before using it to compute the header size, avoiding out-of-bounds access with malformed IP headers. While at it, use iph->protocol instead of the hardcoded IPPROTO_IPIP constant when setting ctx->tun.proto and reference ctx->tun.hdr_size when updating ctx->offset.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxab427db17885814069bae891834f20842f0ac3a4 < 025a41e76b51fbc7b8eaa5bacbaa9621d00e6aa7affected
LinuxLinuxab427db17885814069bae891834f20842f0ac3a4 < 84460b644329e25809b4a6d9279d6359d7fd8ebcaffected
LinuxLinux6.19affected
LinuxLinux0 < 6.19unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References