9.8

CVE-2026-72020

ipvs: reset full ip_vs_seq structs in ip_vs_conn_new

In the Linux kernel, the following vulnerability has been resolved:

ipvs: reset full ip_vs_seq structs in ip_vs_conn_new

Commit 9a05475cebdd ("ipvs: avoid kmem_cache_zalloc in
ip_vs_conn_new") changed ip_vs_conn_new() to allocate an ip_vs_conn
object with kmem_cache_alloc().  The function then initializes many
fields explicitly, but only resets in_seq.delta and out_seq.delta in the
two struct ip_vs_seq members.

That leaves init_seq and previous_delta uninitialized.  This is normally
harmless while the corresponding IP_VS_CONN_F_IN_SEQ or
IP_VS_CONN_F_OUT_SEQ flag is clear.  For connections learned from a sync
message, however, ip_vs_proc_conn() preserves those flags from
IP_VS_CONN_F_BACKUP_MASK and passes opt=NULL when the message omits
IPVS_OPT_SEQ_DATA.  In that case the new connection can be hashed with
SEQ flags set but with the rest of in_seq/out_seq still containing stale
slab data.

When a packet for such a connection is later handled by an IPVS
application helper, vs_fix_seq() and vs_fix_ack_seq() use
previous_delta and init_seq to rewrite TCP sequence numbers.  A malformed
sync message can therefore make forwarded packets carry stale slab bytes
in their TCP seq/ack numbers, and can also corrupt the forwarded TCP
flow.

Reset both struct ip_vs_seq members completely before publishing the
connection.  This matches the existing "reset struct ip_vs_seq" comment
and keeps the sequence-adjustment gates inactive unless valid sequence
data is installed later.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9a05475cebdd6341884b5901e53870be26e65158
Version < 3bf9a260188b2a5449cbddc032a749ab433fe328
Status affected
Version 9a05475cebdd6341884b5901e53870be26e65158
Version < 6378c5cb360eb1750f88839d7c3613ea92ac1816
Status affected
Version 9a05475cebdd6341884b5901e53870be26e65158
Version < 32c299e28b8eea6cbbd23b97dc61401e9ef9c445
Status affected
Version 9a05475cebdd6341884b5901e53870be26e65158
Version < 9e36602cbec552286f7e691cfd366525c565ee74
Status affected
Version 9a05475cebdd6341884b5901e53870be26e65158
Version < d0eed7177e822cab83141e5c44b2aa345c7fd379
Status affected
Version 9a05475cebdd6341884b5901e53870be26e65158
Version < 83fb4c2c5344f02eac929f66de3c9d1adfcde04c
Status affected
Version 9a05475cebdd6341884b5901e53870be26e65158
Version < 6335ab62d5fc9ed875279238233fba3462c168f5
Status affected
Version 9a05475cebdd6341884b5901e53870be26e65158
Version < 2975324d164c552b028632f107b567302863b7f6
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.10
Status affected
Version 0
Version < 3.10
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.7% 0.503
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3bf9a260188b2a5449cbddc032a749ab433fe328
https://git.kernel.org/stable/c/6378c5cb360eb1750f88839d7c3613ea92ac1816
https://git.kernel.org/stable/c/32c299e28b8eea6cbbd23b97dc61401e9ef9c445
https://git.kernel.org/stable/c/9e36602cbec552286f7e691cfd366525c565ee74
https://git.kernel.org/stable/c/d0eed7177e822cab83141e5c44b2aa345c7fd379
https://git.kernel.org/stable/c/83fb4c2c5344f02eac929f66de3c9d1adfcde04c
https://git.kernel.org/stable/c/6335ab62d5fc9ed875279238233fba3462c168f5
https://git.kernel.org/stable/c/2975324d164c552b028632f107b567302863b7f6