Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: use dst in this direction when pushing IPIP header

When pushing the IPIP header, the route of the other direction is used
to calculate the headroom, use the route in this direction. Accessing
the other tuple to set the IP source and destination is fine because
this tuple does not provide such information to avoid storing redundant
information. However, this tuple already provides the dst for this
direction, this went unnoticed because this bug affects headroom and
iph->frag_off only at this stage.
Published: 2026-08-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw arises in the netfilter flowtable IPIP processing path where the kernel incorrectly uses the destination information from the opposite direction when pushing the IPIP header. This misapplication affects only the headroom calculation and the IP fragment offset field early in packet construction. A malformed packet may be produced or the packet may be dropped, potentially disrupting connectivity for IPIP tunnels.

Affected Systems

All Linux kernel installations that enable the netfilter flowtable and IPIP encapsulation are impacted, including generic Linux distributions that ship the kernel without vendor‑specific patches. Any kernel compiling with the default netfilter flowtable code before the fix is affected.

Risk and Exploitability

The EPSS score is <1%, indicating a very low exploitation probability. The vulnerability is not listed in CISA KEV, and the CVSS score is 9.8, placing it in the high severity range. Based on the description, the likely attack vector is a remote or local network‑based exploitation, where an attacker can craft packets that trigger the misuse of the destination address in the IPIP header. The flaw only impacts headroom calculation and the fragment offset field during packet construction. While the exploitability surface appears limited, exploitation could still lead to packet corruption or denial of service by causing the kernel to mis‑handle IPIP tunnel traffic. Since no public exploits are known, monitoring for unusual packet processing errors and applying the kernel update are recommended.

Generated by OpenCVE AI on August 22, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to the latest version that contains the netfilter flowtable fix.
  • Verify that IPIP encapsulation is correctly configured and that routing tables use the appropriate direction; consider re‑evaluating IPIP usage if unnecessary.
  • If immediate patching is not possible, temporarily disable IPIP offloading or remap IPIP traffic through software routing to avoid the affected kernel path.

Generated by OpenCVE AI on August 22, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-131
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Mon, 17 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-665

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-665

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: use dst in this direction when pushing IPIP header When pushing the IPIP header, the route of the other direction is used to calculate the headroom, use the route in this direction. Accessing the other tuple to set the IP source and destination is fine because this tuple does not provide such information to avoid storing redundant information. However, this tuple already provides the dst for this direction, this went unnoticed because this bug affects headroom and iph->frag_off only at this stage.
Title netfilter: flowtable: use dst in this direction when pushing IPIP header
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:42:01.084Z

Reserved: 2026-08-09T03:40:39.914Z

Link: CVE-2026-72249

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:52.150

Modified: 2026-08-17T06:18:26.890

Link: CVE-2026-72249

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72249 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T07:30:17Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size

  • CWE-665

    Improper Initialization