Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: support IPIP tunnel with direct xmit

The combination of IPIP tunnel with direct xmit, eg. bridge device,
breaks because no dst_entry is provided to check the skb headroom and to
set the iph->frag_off field. This leads to invalid dst usage and can
trigger a crash in the tunnel transmit path.

Fix this by moving dst_cache and dst_cookie out of the runtime union so
that they can be shared by neighbour, xfrm, and direct tunnel flows.
For FLOW_OFFLOAD_XMIT_DIRECT tuples carrying tunnel metadata, preserve
route state in these shared fields and release it through the common
dst release path.

Since dst_entry is now available to the three supported xmit modes and
dst_release() already deals with NULL dst, remove the xmit type check
in nft_flow_dst_release(). Moreover, skip the check if the dst entry
is NULL in nf_flow_dst_check() which is now the case for the direct
xmit case.

Based on patch from Rein Wei <n05ec@lzu.edu.cn>.
Published: 2026-08-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel’s flowtable module incorrectly handles IPIP tunnel packets that are transmitted directly, such as when a bridge device forwards them. Because a destination entry is missing, the code does not verify packet headroom or set the IP fragmentation field, leading to the use of an invalid destination cache. This flaw triggers a kernel crash during the tunnel transmit path and results in a denial of service by abruptly halting kernel operations.

Affected Systems

All Linux kernel implementations compiled with the flowtable module that support IPIP tunnels using the direct transmit mode are affected. No specific kernel versions are enumerated, so any pre‑patch kernel that follows this flowtable path is vulnerable. The vendor list indicates the ubiquitous Linux kernel across all distributions, meaning any system running such a kernel is impacted.

Risk and Exploitability

A CVSS score of 9.8 indicates critical severity, while an EPSS score of less than 1% points to a low exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to send crafted IPIP packets to a host that forwards such traffic through a bridge or similar path. The exploitation requires the target to accept and forward IPIP traffic, constituting a remote network attack vector. Although the complexity is moderate, the kernel crash it causes makes it a high‑impact threat.

Generated by OpenCVE AI on August 18, 2026 at 04:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the commit which moves dst_cache and dst_cookie out of the runtime union, restoring proper destination handling.
  • If a kernel upgrade cannot be performed, block inbound IPIP traffic or disable IPIP tunnel support in the network configuration to prevent the direct transmit code path from being exercised.
  • As a last resort, manually back‑port the source code changes that establish and release destination entries correctly and adjust the flowtable logic accordingly.

Generated by OpenCVE AI on August 18, 2026 at 04:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-682

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-824
References
Metrics threat_severity

None

threat_severity

Important


Mon, 17 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-682

Mon, 17 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: support IPIP tunnel with direct xmit The combination of IPIP tunnel with direct xmit, eg. bridge device, breaks because no dst_entry is provided to check the skb headroom and to set the iph->frag_off field. This leads to invalid dst usage and can trigger a crash in the tunnel transmit path. Fix this by moving dst_cache and dst_cookie out of the runtime union so that they can be shared by neighbour, xfrm, and direct tunnel flows. For FLOW_OFFLOAD_XMIT_DIRECT tuples carrying tunnel metadata, preserve route state in these shared fields and release it through the common dst release path. Since dst_entry is now available to the three supported xmit modes and dst_release() already deals with NULL dst, remove the xmit type check in nft_flow_dst_release(). Moreover, skip the check if the dst entry is NULL in nf_flow_dst_check() which is now the case for the direct xmit case. Based on patch from Rein Wei <n05ec@lzu.edu.cn>.
Title netfilter: flowtable: support IPIP tunnel with direct xmit
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:41:59.975Z

Reserved: 2026-08-09T03:40:39.914Z

Link: CVE-2026-72248

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:52.030

Modified: 2026-08-17T06:18:26.757

Link: CVE-2026-72248

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72248 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T04:30:06Z

Weaknesses
  • CWE-824

    Access of Uninitialized Pointer