ipvs: clear IPv4 options after rebasing tunnel ICMP errors
Summary
| CVE | CVE-2026-74669 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-22 16:16:40 UTC |
| Updated | 2026-08-25 06:18:49 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: ipvs: clear IPv4 options after rebasing tunnel ICMP errors ip_vs_in_icmp() rebases an skb from the outer ICMP packet to the quoted original request before passing it to icmp_send(). However, IPCB(skb)->opt still describes the outer IPv4 header. A timestamp option in the outer header can therefore leave an offset that points into the quoted transport header after the rebase. __ip_options_echo() treats a byte at that stale location as the option length and copies it into the fixed-size option storage on the __icmp_send() stack, causing a stack out-of-bounds write. Clear the stale option metadata after resetting the network header. Keep the remaining control block fields, including the ingress interface used by the ICMP response path. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.005140000 probability, percentile 0.414760000 (date 2026-08-25)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e 79ffa99202c944467e28b13b513bf2998732edff git | Not specified |
| CNA | Linux | Linux | affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e c9413b50204738fbc429bb86bf01353c393a6c28 git | Not specified |
| CNA | Linux | Linux | affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e 37c61b3745129cbd682c557b51345828120972e5 git | Not specified |
| CNA | Linux | Linux | affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e ed246dd85ebf27c1f6b7897834d40786c0ca3006 git | Not specified |
| CNA | Linux | Linux | affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e 6f46fc460e9316062bdcdf89199eb5d7a33da33b git | Not specified |
| CNA | Linux | Linux | affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e 75eec935444db4af2123e0491936f6e273d7ea00 git | Not specified |
| CNA | Linux | Linux | affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e 384b4dae14277d369221d187e9b3af56c79d2e50 git | Not specified |
| CNA | Linux | Linux | affected f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e e0ba936287dfe9783426aac27e5fd76fe35b38c9 git | Not specified |
| CNA | Linux | Linux | affected 3.7 | Not specified |
| CNA | Linux | Linux | unaffected 3.7 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.265 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.216 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.183 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.152 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.104 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.45 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.9 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/37c61b3745129cbd682c557b51345828120972e5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c9413b50204738fbc429bb86bf01353c393a6c28 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e0ba936287dfe9783426aac27e5fd76fe35b38c9 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/79ffa99202c944467e28b13b513bf2998732edff | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6f46fc460e9316062bdcdf89199eb5d7a33da33b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/384b4dae14277d369221d187e9b3af56c79d2e50 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/75eec935444db4af2123e0491936f6e273d7ea00 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ed246dd85ebf27c1f6b7897834d40786c0ca3006 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.