CVE-2026-97417

Summary

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()

The timestamp-only fast path dereferences the option stream as *(__be32 *)ptr, which assumes 4-byte alignment that the TCP option stream does not guarantee. Use get_unaligned_be32() instead, which reads the value safely and already returns host byte order, so the htonl() on the comparison constant can be dropped.

This matches the existing get_unaligned_be32() use later in the same function.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxbb9fc37358ffa9de1cc2b2b6f1a559b926ef50d9 < 7ecfa46a536578a7ed335ddf31a854127268c27caffected
LinuxLinuxbb9fc37358ffa9de1cc2b2b6f1a559b926ef50d9 < 4abc1af7ac209c066f4e5dd75cdd56876e5829a9affected
LinuxLinuxbb9fc37358ffa9de1cc2b2b6f1a559b926ef50d9 < d3bf9eae486490832bd08fd62ab0ac601f346bd4affected
LinuxLinux3.1affected
LinuxLinux0 < 3.1unaffected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References