netfilter: synproxy: fix unaligned memory access in timestamp adjustment
Summary
| CVE | CVE-2026-80637 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-28 08:16:48 UTC |
| Updated | 2026-08-28 08:16:48 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: fix unaligned memory access in timestamp adjustment Use get_unaligned_be32() and put_unaligned_be32() to safely read and write the timestamp fields. This prevents performance degradation due to unaligned memory access or even a crash on strict alignment architectures. This follows the implementation of timestamp parsing in the networking stack at tcp_parse_options() and synproxy_parse_options(). |
Risk And Classification
EPSS: 0.001680000 probability, percentile 0.062700000 (date 2026-08-28)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 48b1de4c110a7afa4b85862f6c75af817db26fad 2b8e7aaa38002d8ee2f48d87b1f392eadd8e98c4 git | Not specified |
| CNA | Linux | Linux | affected 48b1de4c110a7afa4b85862f6c75af817db26fad 5c9c67cf7a3d16051dfb90e98836f530964dfb8e git | Not specified |
| CNA | Linux | Linux | affected 48b1de4c110a7afa4b85862f6c75af817db26fad ea3d2caa5bfacf5db5c1cad521ca5d9144edd9a7 git | Not specified |
| CNA | Linux | Linux | affected 48b1de4c110a7afa4b85862f6c75af817db26fad 992c20bc8a4aba220c8b95b467d049289778dad6 git | Not specified |
| CNA | Linux | Linux | affected 3.12 | Not specified |
| CNA | Linux | Linux | unaffected 3.12 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.97 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.40 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.5 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/5c9c67cf7a3d16051dfb90e98836f530964dfb8e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/992c20bc8a4aba220c8b95b467d049289778dad6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/2b8e7aaa38002d8ee2f48d87b1f392eadd8e98c4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ea3d2caa5bfacf5db5c1cad521ca5d9144edd9a7 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.