๐Ÿ” CVE Alert

CVE-2026-72250

UNKNOWN 0.0

netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag nf_ct_frag6_reasm() slides the packet head forward to drop the IPv6 fragment header and then unconditionally advances skb->mac_header: skb->mac_header += sizeof(struct frag_hdr); On the NF_INET_LOCAL_OUT defrag path the skb has no link-layer header yet, so skb->mac_header is still the "not set" sentinel (u16)~0U. Adding sizeof(struct frag_hdr) wraps it to a small value (0xffff + 8 == 7), after which skb_mac_header_was_set() wrongly reports a MAC header is present and skb_mac_header() points into the headroom. The reassembler has done this unconditional add since it was introduced; it was harmless while mac_header was a bare pointer, but wrong once mac_header became a u16 offset whose unset state is the ~0U sentinel tested by skb_mac_header_was_set(). The sibling net/ipv6/reassembly.c does the same relocation and does guard the adjustment; mirror the guard here.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1 < 6e8cd710ca35c576f5f2e5a396047c9ac61f75e5 9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1 < 2a95ec21824a8ad81ad660b12231456fc0ac9830 9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1 < bbcdef2061b170af45702ce6b359c02c12acfc94 9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1 < cd0d7bbc027b4d3329712cdcdeb4e5567ffd0d58 9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1 < 53ef70a315420ed31581d38343684b3bf9a3c76d 9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1 < a58230f3a7c4f6c3261786bc1efb72c42e68cd25 9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1 < 00bdce2fda7e430d24cfbc96764a1b96deb31f82 9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1 < 3b08fed5b7e0d5e3a25d73ef3ba09cd33ade16c9
Linux / Linux
2.6.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/6e8cd710ca35c576f5f2e5a396047c9ac61f75e5 git.kernel.org: https://git.kernel.org/stable/c/2a95ec21824a8ad81ad660b12231456fc0ac9830 git.kernel.org: https://git.kernel.org/stable/c/bbcdef2061b170af45702ce6b359c02c12acfc94 git.kernel.org: https://git.kernel.org/stable/c/cd0d7bbc027b4d3329712cdcdeb4e5567ffd0d58 git.kernel.org: https://git.kernel.org/stable/c/53ef70a315420ed31581d38343684b3bf9a3c76d git.kernel.org: https://git.kernel.org/stable/c/a58230f3a7c4f6c3261786bc1efb72c42e68cd25 git.kernel.org: https://git.kernel.org/stable/c/00bdce2fda7e430d24cfbc96764a1b96deb31f82 git.kernel.org: https://git.kernel.org/stable/c/3b08fed5b7e0d5e3a25d73ef3ba09cd33ade16c9