๐Ÿ” CVE Alert

CVE-2026-72417

UNKNOWN 0.0

netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() Add sanity check for iph->ihl field in nf_flow_ip4_tunnel_proto() before using it to compute the header size, avoiding out-of-bounds access with malformed IP headers. While at it, use iph->protocol instead of the hardcoded IPPROTO_IPIP constant when setting ctx->tun.proto and reference ctx->tun.hdr_size when updating ctx->offset.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
ab427db17885814069bae891834f20842f0ac3a4 < 025a41e76b51fbc7b8eaa5bacbaa9621d00e6aa7 ab427db17885814069bae891834f20842f0ac3a4 < 84460b644329e25809b4a6d9279d6359d7fd8ebc
Linux / Linux
6.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/025a41e76b51fbc7b8eaa5bacbaa9621d00e6aa7 git.kernel.org: https://git.kernel.org/stable/c/84460b644329e25809b4a6d9279d6359d7fd8ebc