ipvs: clear IPv4 options after rebasing tunnel ICMP errors
Summary
| CVE | CVE-2026-74669 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-22 16:16:40 UTC |
| Updated | 2026-08-22 16:16:40 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
ipvs: clear IPv4 options after rebasing tunnel ICMP errors
ip_vs_in_icmp() rebases an skb from the outer ICMP packet to the
quoted original request before passing it to icmp_send(). However,
IPCB(skb)->opt still describes the outer IPv4 header.
A timestamp option in the outer header can therefore leave an offset
that points into the quoted transport header after the rebase.
__ip_options_echo() treats a byte at that stale location as the option
length and copies it into the fixed-size option storage on the
__icmp_send() stack, causing a stack out-of-bounds write.
Clear the stale option metadata after resetting the network header.
Keep the remaining control block fields, including the ingress
interface used by the ICMP response path. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e 79ffa99202c944467e28b13b513bf2998732edff git |
Not specified |
| CNA |
Linux |
Linux |
affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e c9413b50204738fbc429bb86bf01353c393a6c28 git |
Not specified |
| CNA |
Linux |
Linux |
affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e 37c61b3745129cbd682c557b51345828120972e5 git |
Not specified |
| CNA |
Linux |
Linux |
affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e ed246dd85ebf27c1f6b7897834d40786c0ca3006 git |
Not specified |
| CNA |
Linux |
Linux |
affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e 6f46fc460e9316062bdcdf89199eb5d7a33da33b git |
Not specified |
| CNA |
Linux |
Linux |
affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e 75eec935444db4af2123e0491936f6e273d7ea00 git |
Not specified |
| CNA |
Linux |
Linux |
affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e 384b4dae14277d369221d187e9b3af56c79d2e50 git |
Not specified |
| CNA |
Linux |
Linux |
affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e e0ba936287dfe9783426aac27e5fd76fe35b38c9 git |
Not specified |
| CNA |
Linux |
Linux |
affected 3.7 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 3.7 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.265 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.216 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.183 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.152 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.104 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.45 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.9 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/37c61b3745129cbd682c557b51345828120972e5 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/c9413b50204738fbc429bb86bf01353c393a6c28 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e0ba936287dfe9783426aac27e5fd76fe35b38c9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/79ffa99202c944467e28b13b513bf2998732edff |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6f46fc460e9316062bdcdf89199eb5d7a33da33b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/384b4dae14277d369221d187e9b3af56c79d2e50 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/75eec935444db4af2123e0491936f6e273d7ea00 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ed246dd85ebf27c1f6b7897834d40786c0ca3006 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.