๐Ÿ” CVE Alert

CVE-2026-80793

UNKNOWN 0.0

ipv4: reject undersized MTUs in ip_do_fragment()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ipv4: reject undersized MTUs in ip_do_fragment() ip_do_fragment() subtracts the IPv4 header length from the effective MTU and passes the resulting payload MTU to ip_frag_next(). If the effective MTU is smaller than hlen + 8, ip_frag_next() rounds the fragment payload length down to zero. The fragmentation state then never makes forward progress: state->left, state->ptr and state->offset stay unchanged while ip_do_fragment() keeps allocating and transmitting header-only fragments until the softlockup detector fires. This is reproducible with a route installed using "mtu lock 20", but it is also reproducible without route MTU lock, for example by forwarding a packet to a device whose MTU is 20. Fix it in ip_do_fragment() by rejecting mtu < hlen + 8 with -EMSGSIZE, matching the existing IPv6 fragmentation check.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a716a64a4ba68cd46f2745fba2b1099fe8e0aa59 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 515b6816ba0c12d8415c88e5f41e6ec029e35cfa 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 74ce7389f8f562d39015f59a00ef7ad6acd37803 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b0ea911453ce7210e8200a07a94d2458bd1e6430 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 36e0741833bd823866f8cb9f112f37cea1a70b60 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d9d1a676b033acabf8e5645f730486d1f8204a3f 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3556beb8ca86677af2aca5bfbed6f8e790fccc83 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c8a74adccaf028223054633b532593101dfcc581 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c0726f0caf8c6b3208552949e17d23634a2f3129
Linux / Linux
2.6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a716a64a4ba68cd46f2745fba2b1099fe8e0aa59 git.kernel.org: https://git.kernel.org/stable/c/515b6816ba0c12d8415c88e5f41e6ec029e35cfa git.kernel.org: https://git.kernel.org/stable/c/74ce7389f8f562d39015f59a00ef7ad6acd37803 git.kernel.org: https://git.kernel.org/stable/c/b0ea911453ce7210e8200a07a94d2458bd1e6430 git.kernel.org: https://git.kernel.org/stable/c/36e0741833bd823866f8cb9f112f37cea1a70b60 git.kernel.org: https://git.kernel.org/stable/c/d9d1a676b033acabf8e5645f730486d1f8204a3f git.kernel.org: https://git.kernel.org/stable/c/3556beb8ca86677af2aca5bfbed6f8e790fccc83 git.kernel.org: https://git.kernel.org/stable/c/c8a74adccaf028223054633b532593101dfcc581 git.kernel.org: https://git.kernel.org/stable/c/c0726f0caf8c6b3208552949e17d23634a2f3129