{"api_version":"1","generated_at":"2026-09-29T06:43:39+00:00","cve":"CVE-2026-97596","urls":{"html":"https://cve.report/CVE-2026-97596","api":"https://cve.report/api/cve/CVE-2026-97596.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-97596","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-97596"},"summary":{"title":"ipvs: reject invalid states in connection template sync records","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: reject invalid states in connection template sync records\n\nIPVS sync receivers validate protocol states before creating or updating a\nconnection. For connection templates, however, they only log states outside\nthe template state range and still store the value in the connection.\n\nA template can be returned by ordinary connection lookup. TCP and SCTP then\nuse the invalid state as an index into their transition tables.\n\nReject invalid template states in both sync protocol versions before\nlooking up or modifying a connection. The version 1 path handles both\nIPv4 and IPv6 records.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-25 11:17:10","updated_at":"2026-09-25 11:17:10"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/74cb39735b6cd0aff4b5584158f09376fd97aadf","name":"https://git.kernel.org/stable/c/74cb39735b6cd0aff4b5584158f09376fd97aadf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0c61f7d8e18a978aec2a16d9acd5f682f1c72476","name":"https://git.kernel.org/stable/c/0c61f7d8e18a978aec2a16d9acd5f682f1c72476","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/fc10dc4511e6e2e2b4098ee115c8e5639471f23d","name":"https://git.kernel.org/stable/c/fc10dc4511e6e2e2b4098ee115c8e5639471f23d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/50c3f06222eafe9cca7ca51a0ef83311d7cab353","name":"https://git.kernel.org/stable/c/50c3f06222eafe9cca7ca51a0ef83311d7cab353","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97596","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97596","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 275411430f892407b885be1de2548b2e632892c3 fc10dc4511e6e2e2b4098ee115c8e5639471f23d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 275411430f892407b885be1de2548b2e632892c3 50c3f06222eafe9cca7ca51a0ef83311d7cab353 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 275411430f892407b885be1de2548b2e632892c3 0c61f7d8e18a978aec2a16d9acd5f682f1c72476 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 275411430f892407b885be1de2548b2e632892c3 74cb39735b6cd0aff4b5584158f09376fd97aadf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.19","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.19 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.111 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.7 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc3 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"97596","cve":"CVE-2026-97596","epss":"0.002000000","percentile":"0.088120000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:24"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/netfilter/ipvs/ip_vs_sync.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"fc10dc4511e6e2e2b4098ee115c8e5639471f23d","status":"affected","version":"275411430f892407b885be1de2548b2e632892c3","versionType":"git"},{"lessThan":"50c3f06222eafe9cca7ca51a0ef83311d7cab353","status":"affected","version":"275411430f892407b885be1de2548b2e632892c3","versionType":"git"},{"lessThan":"0c61f7d8e18a978aec2a16d9acd5f682f1c72476","status":"affected","version":"275411430f892407b885be1de2548b2e632892c3","versionType":"git"},{"lessThan":"74cb39735b6cd0aff4b5584158f09376fd97aadf","status":"affected","version":"275411430f892407b885be1de2548b2e632892c3","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/netfilter/ipvs/ip_vs_sync.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.19"},{"lessThan":"4.19","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.111","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.7","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc3","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.111","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.7","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc3","versionStartIncluding":"4.19","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: reject invalid states in connection template sync records\n\nIPVS sync receivers validate protocol states before creating or updating a\nconnection. For connection templates, however, they only log states outside\nthe template state range and still store the value in the connection.\n\nA template can be returned by ordinary connection lookup. TCP and SCTP then\nuse the invalid state as an index into their transition tables.\n\nReject invalid template states in both sync protocol versions before\nlooking up or modifying a connection. The version 1 path handles both\nIPv4 and IPv6 records."}],"providerMetadata":{"dateUpdated":"2026-09-25T10:22:11.784Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/fc10dc4511e6e2e2b4098ee115c8e5639471f23d"},{"url":"https://git.kernel.org/stable/c/50c3f06222eafe9cca7ca51a0ef83311d7cab353"},{"url":"https://git.kernel.org/stable/c/0c61f7d8e18a978aec2a16d9acd5f682f1c72476"},{"url":"https://git.kernel.org/stable/c/74cb39735b6cd0aff4b5584158f09376fd97aadf"}],"title":"ipvs: reject invalid states in connection template sync records","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-97596","datePublished":"2026-09-25T10:22:11.784Z","dateReserved":"2026-09-24T16:01:01.157Z","dateUpdated":"2026-09-25T10:22:11.784Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-25 11:17:10","lastModifiedDate":"2026-09-25 11:17:10","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"97596","Ordinal":"1","Title":"ipvs: reject invalid states in connection template sync records","CVE":"CVE-2026-97596","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"97596","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: reject invalid states in connection template sync records\n\nIPVS sync receivers validate protocol states before creating or updating a\nconnection. For connection templates, however, they only log states outside\nthe template state range and still store the value in the connection.\n\nA template can be returned by ordinary connection lookup. TCP and SCTP then\nuse the invalid state as an index into their transition tables.\n\nReject invalid template states in both sync protocol versions before\nlooking up or modifying a connection. The version 1 path handles both\nIPv4 and IPv6 records.","Type":"Description","Title":"ipvs: reject invalid states in connection template sync records"}]}}}