๐Ÿ” CVE Alert

CVE-2026-80901

UNKNOWN 0.0

ipvs: fix the checksum validations

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ipvs: fix the checksum validations ip_vs_in_icmp_v6() is missing checksum validation for ICMPv6 packets from clients. In fact, as for TCP/UDP we should validate the checksum for ICMP packets only when we mangle the packets on MASQ or on reply for tunnel. Also, Sashiko points out that handle_response_icmp() being common for IPv4 and IPv6 is missing the pseudo-header calculation while validating ICMPv6 messages from real servers which is a problem if checksum is not validated by the hardware. Fix the problems by creating ip_vs_checksum_common_check() helper and use it for TCP/UDP/ICMP both for IPv4 and IPv6. Rely on the nf_checksum() for validating the ICMP messages but use it also for TCP and UDP. Use correct IP offset for IP_VS_DBG_RL_PKT for TCP/UDP/SCTP. IPVS packets (TCP/UDP/SCTP/ICMP) do not need checksum validation on LOCAL_OUT (local clients or local real servers) and on FORWARD (traffic from servers on LAN). Do it only on LOCAL_IN, in case nf_checksum() is not called on PRE_ROUTING. Also, ip_vs_checksum_complete() can be marked static.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
2a3b791e6e1169f374224d164738e9f7be703d77 < d418d73acf8be62744dc47359dfdde8c2148845d 2a3b791e6e1169f374224d164738e9f7be703d77 < b3869d9b54e76dff64118dee4c8fd9302fcd5171 2a3b791e6e1169f374224d164738e9f7be703d77 < 9cbe2c0fdb71904ee929b1851cdc1c73341a03c0 2a3b791e6e1169f374224d164738e9f7be703d77 < 00eb23829fd08df1b5e057cb6b625996a70e7e65 2a3b791e6e1169f374224d164738e9f7be703d77 < 5558a85add073215b298f3e044ff9a6d86d714ae 2a3b791e6e1169f374224d164738e9f7be703d77 < e876b75b9020a97bbdc79721e7fc749024891c65
Linux / Linux
2.6.28

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d418d73acf8be62744dc47359dfdde8c2148845d git.kernel.org: https://git.kernel.org/stable/c/b3869d9b54e76dff64118dee4c8fd9302fcd5171 git.kernel.org: https://git.kernel.org/stable/c/9cbe2c0fdb71904ee929b1851cdc1c73341a03c0 git.kernel.org: https://git.kernel.org/stable/c/00eb23829fd08df1b5e057cb6b625996a70e7e65 git.kernel.org: https://git.kernel.org/stable/c/5558a85add073215b298f3e044ff9a6d86d714ae git.kernel.org: https://git.kernel.org/stable/c/e876b75b9020a97bbdc79721e7fc749024891c65