Description
In the Linux kernel, the following vulnerability has been resolved:

ipvs: fix integer overflow in ftp helper port/address parsing

ip_vs_ftp_get_addrport() accumulates decimal digits into a __u16
(hport) and into unsigned char (p[]) without checking for overflow.
A crafted FTP PASV/EPSV response with an over-long port or address
octet wraps the value, so the helper configures the data connection
with a truncated port/address.

The netfilter conntrack FTP helper had the same defect, fixed in
commit 2b413fc689ba ("netfilter: nf_conntrack_ftp: avoid u16
overflows"). Apply the equivalent fix here: widen the port accumulator
to u32 and reject values above 65535, and reject address octets above
255.
Published: 2026-09-17
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Invalid port and address parsing in IPVS FTP helper
Action: Immediate Patch
AI Analysis

Impact

The flaw arises when the IPVS FTP helper parses a FTP PASV or EPSV response that contains exceedingly long numeric fields. The helper accumulates digits into a 16‑bit variable and into an unsigned byte array without bounds checks, allowing an overflow that truncates the port or address values. This could result in the helper establishing a data connection using incorrect parameters, potentially allowing an attacker to influence the data link or bypass expected filtering. The vulnerability is an integer overflow, and it directly impacts the integrity of data connections established by IPVS.

Affected Systems

Affected systems are Linux kernel users that employ the IPVS FTP helper. The vulnerability is present in any kernel build that does not include the commit that widens the accumulator to a 32‑bit integer and rejects values above the legal limits. The specific versions affected are not listed in the advisory, so any kernel prior to the application of the fix is considered vulnerable.

Risk and Exploitability

The risk is rated as a high‑severity CVSS score of 7.3 with an exploit probability of less than one percent according to EPSS. The vulnerability is not listed in CISA’s KEV catalog. The attack requires an attacker to send a specially crafted FTP PASV or EPSV reply to a host that is running the IPVS FTP helper, so the vector is network‑based and contingent on the helper being active.

Generated by OpenCVE AI on September 20, 2026 at 02:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that incorporates the integer overflow fix in ipvs_ftp_get_addrport
  • Restart or reload the kernel module so the patched code takes effect
  • If a kernel update cannot be applied immediately, disable the IPVS FTP helper to remove the vulnerable code path

Generated by OpenCVE AI on September 20, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ipvs: fix integer overflow in ftp helper port/address parsing ip_vs_ftp_get_addrport() accumulates decimal digits into a __u16 (hport) and into unsigned char (p[]) without checking for overflow. A crafted FTP PASV/EPSV response with an over-long port or address octet wraps the value, so the helper configures the data connection with a truncated port/address. The netfilter conntrack FTP helper had the same defect, fixed in commit 2b413fc689ba ("netfilter: nf_conntrack_ftp: avoid u16 overflows"). Apply the equivalent fix here: widen the port accumulator to u32 and reject values above 65535, and reject address octets above 255.
Title ipvs: fix integer overflow in ftp helper port/address parsing
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:18.468Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90141

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:06.857

Modified: 2026-09-18T18:17:43.397

Link: CVE-2026-90141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound