Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()

Add sanity check for iph->ihl field in nf_flow_ip4_tunnel_proto() before
using it to compute the header size, avoiding out-of-bounds access with
malformed IP headers.
While at it, use iph->protocol instead of the hardcoded IPPROTO_IPIP
constant when setting ctx->tun.proto and reference ctx->tun.hdr_size
when updating ctx->offset.
Published: 2026-08-15
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The netfilter flowtable component of the Linux kernel contains a flaw in nf_flow_ip4_tunnel_proto() where the IP header length field, iph->ihl, is used unvalidated to calculate the packet header size. An attacker can craft a packet with an overly large ihl value, causing the kernel to read beyond the bounds of the packet buffer. This out‑of‑bounds read may leak kernel memory and, if combined with an auxiliary write primitive, could enable arbitrary code execution or a denial of service at the kernel level.

Affected Systems

All Linux kernel releases that include the netfilter flowtable module are potentially affected. The patch commit that introduces the ihl sanity check was published in the kernel source repository (see the provided Git links), but no specific version range is listed. Therefore any kernel that has not yet incorporated the commits identified by the hashes 025a41e76b51fbc7b8eaa5bacbaa9621d00e6aa7 or 84460b644329e25809b4a6d9279d6359d7fd8ebc should be considered vulnerable.

Risk and Exploitability

No publicly documented exploits are available and the EPSS score is not provided, yet the lack of input validation implies a high severity. Attackers can exploit this over the network by sending crafted IP packets to a target system that has the vulnerable flowtable code active. Because the flaw occurs in the kernel, successful exploitation could provide elevated privileges or complete system compromise. The vulnerability is not yet listed in the CISA KEV catalog, indicating no confirmed exploitation to date.

Generated by OpenCVE AI on August 15, 2026 at 11:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes commit 025a41e76b51fbc7b8eaa5bacbaa9621d00e6aa7 or 84460b644329e25809b4a6d9279d6359d7fd8ebc, which adds the ihl sanity check.
  • If a kernel upgrade cannot be performed immediately, disable the flowtable module or IPv4 tunneling functions that rely on nf_flow_ip4_tunnel_proto() to eliminate the attack surface until the patch is applied.
  • Implement network monitoring or firewall rules that restrict unexpected or anomalous IP packet traffic to reduce the likelihood of an attacker delivering exploited packets.

Generated by OpenCVE AI on August 15, 2026 at 11:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() Add sanity check for iph->ihl field in nf_flow_ip4_tunnel_proto() before using it to compute the header size, avoiding out-of-bounds access with malformed IP headers. While at it, use iph->protocol instead of the hardcoded IPPROTO_IPIP constant when setting ctx->tun.proto and reference ctx->tun.hdr_size when updating ctx->offset.
Title netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:56:37.547Z

Reserved: 2026-08-09T03:40:39.927Z

Link: CVE-2026-72417

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:15.323

Modified: 2026-08-15T06:22:15.323

Link: CVE-2026-72417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T11:15:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer