{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74747","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.931Z","datePublished":"2026-08-26T14:36:56.563Z","dateUpdated":"2026-08-27T05:01:08.455Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-27T05:01:08.455Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: revalidate ihl to prevent out-of-bounds access\n\nWhile the outer IP header is already pulled into the skb head,\nwe must be careful and revalidate the embedded headers after\nreading them from the skb frags to prevent out-of-bounds\naccess.\n\nOne such place reported by Sashiko is ip_vs_nat_icmp() where\nlocal process can change the ihl field and after\nskb_ensure_writable() we can see larger value which is a\nproblem for the ip_send_check(cih) calls.\n\nAdd check to drop the packet if the ihl field is changed."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires a local process to TOCTOU-modify the embedded IPv4 ihl in skb frags between ip_vs_fill_iph_skb_icmp() and skb_ensure_writable(); remote ICMP to IPVS NAT hooks reaches ip_vs_nat_icmp() but cannot change skb backing memory without local access to the packet buffer.\nAC:L - A local attacker controls both sides of the race by concurrently injecting ICMP errors matching an IPVS NAT connection and mutating the embedded header ihl in userspace-backed skb frags during softirq processing; no uncontrollable victim state or heap layout is required.\nPR:L - Only a local account able to race skb frag modification (e.g., via raw/packet sockets with CAP_NET_RAW obtainable in user namespaces) against IPVS ICMP NAT handling on a host where IPVS is already configured is needed; init-namespace root is not required.\nUI:N - No victim user interaction is required; exploitation is driven entirely by attacker-controlled local packet injection and concurrent frag modification while IPVS processes ICMP errors on NAT-mode connections through LOCAL_IN, LOCAL_OUT, or FORWARD hooks.\nS:U - The out-of-bounds access corrupts kernel skb memory on the IPVS load-balancer host within the same kernel security authority; it does not cross VM, container, or IOMMU boundaries into a separate security scope.\nC:H - After skb_ensure_writable(), ip_send_check(cih) re-reads an attacker-inflated cih->ihl and ip_fast_csum() reads far beyond the validated skb region, enabling out-of-bounds kernel memory disclosure on internet-facing IPVS NAT nodes and kube-proxy IPVS clusters.\nI:H - The inflated ihl causes out-of-bounds access during ICMP NAT mangling in ip_vs_nat_icmp(), corrupting skb data beyond skb_ensure_writable()'s bound; such kernel memory corruption is exploitable for control-flow hijacking and privilege escalation on load balancers.\nA:H - Out-of-bounds access in ip_send_check(cih) during ICMP NAT handling can trigger kernel oops or panic; a local attacker can repeatedly race the TOCTOU on IPVS NAT nodes, causing sustained denial of service on critical infrastructure."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/ip_vs.h","net/netfilter/ipvs/ip_vs_core.c","net/netfilter/ipvs/ip_vs_xmit.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5365f012451fce2453f13a568dcb72ea534c1e4d","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d93660df4dd1d116f608ada4a29a80a5d6f0a6ed","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/ip_vs.h","net/netfilter/ipvs/ip_vs_core.c","net/netfilter/ipvs/ip_vs_xmit.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.1.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5365f012451fce2453f13a568dcb72ea534c1e4d"},{"url":"https://git.kernel.org/stable/c/d93660df4dd1d116f608ada4a29a80a5d6f0a6ed"}],"title":"ipvs: revalidate ihl to prevent out-of-bounds access","x_generator":{"engine":"bippy-1.2.0"}}}}