{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80714","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.788Z","datePublished":"2026-08-28T06:53:13.069Z","dateUpdated":"2026-08-29T06:22:30.808Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-29T06:22:30.808Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: do not propagate one-packet flag to synced conns\n\nSynced connections can be created before their destination exists. When\nthe destination is later added, ip_vs_bind_dest() copies connection flags\nfrom the destination into cp->flags.\n\nIP_VS_CONN_F_ONE_PACKET connections are not synced. If a synced\nconnection inherits IP_VS_CONN_F_ONE_PACKET while it is already hashed,\nexpiry can treat it as a one-packet connection and skip unlinking the\nexisting conn_tab node, leaving stale hash nodes pointing at a freed\nstruct ip_vs_conn.\n\nDrop IP_VS_CONN_F_ONE_PACKET from destination flags when binding synced\nconnections."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The bug is reached on IPVS backup nodes processing UDP sync datagrams in ip_vs_process_message()/ip_vs_proc_conn() (default multicast 224.0.0.81:8848), and on internet-facing load balancers client UDP traffic drives master sync that creates the hashed backup connection before destination bind.\nAC:L - An attacker can reliably inject or refresh IPVS sync records for UDP connections whose destination is not yet present, then trigger ip_vs_try_bind_dest() once a ONEPACKET destination exists; only optional syncid filtering (often 0) is outside attacker control, and connection expiry is timer-driven without a race.\nPR:N - The backup sync receiver accepts unauthenticated UDP multicast with no capability checks in ip_vs_receive()/ip_vs_process_message(); configuring IPVS/ONEPACKET is an environmental precondition on HA load balancers, not a privilege the remote attacker must hold on the victim host.\nUI:N - Exploitation requires no victim or administrator action at trigger time beyond normal HA IPVS operation; forged or reflected sync traffic and subsequent connection expiry directly invoke the vulnerable bind/unlink path without user interaction.\nS:U - Impact is confined to the kernel IPVS connection table on the affected load-balancer node (stale hash entries to a freed struct ip_vs_conn); it does not cross a VM, container, or IOMMU security boundary.\nC:H - Incorrect ONE_PACKET handling leaves hashed conn_tab nodes pointing at a freed struct ip_vs_conn; subsequent lookups in __ip_vs_conn_in_get() dereference freed slab memory, giving a use-after-free read primitive and potential kernel pointer/data disclosure.\nI:H - The same use-after-free lets attackers influence reuse of the freed ip_vs_conn object and corrupt connection state during later hash-table operations, enabling memory corruption exploitable for arbitrary kernel writes or control-flow hijacking.\nA:H - Dereferencing stale conn_tab entries for a freed connection causes kernel oops/panic; the condition is repeatable by sending additional sync traffic to recreate and expire affected UDP synced connections on the backup node."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/ipvs/ip_vs_conn.c"],"versions":[{"version":"26ec037f9841e49cc5c615deb8e1e73e5beab2ca","lessThan":"06d1d9b56ef8132fbf85006885eb43d9510b8b02","status":"affected","versionType":"git"},{"version":"26ec037f9841e49cc5c615deb8e1e73e5beab2ca","lessThan":"acbdc276091b308ca7794acb86e761f8203e2f59","status":"affected","versionType":"git"},{"version":"26ec037f9841e49cc5c615deb8e1e73e5beab2ca","lessThan":"300348e3ba1521b003d59825f97e24f9a6859688","status":"affected","versionType":"git"},{"version":"26ec037f9841e49cc5c615deb8e1e73e5beab2ca","lessThan":"44af98cc7d5ef8e730488d5df1eecd5deeaa5947","status":"affected","versionType":"git"},{"version":"26ec037f9841e49cc5c615deb8e1e73e5beab2ca","lessThan":"4649e6faeecdc2d44bfa6ccbe405eef27e55d816","status":"affected","versionType":"git"},{"version":"26ec037f9841e49cc5c615deb8e1e73e5beab2ca","lessThan":"b5ee5b266f833601ac4817f6df0bc496fc376a28","status":"affected","versionType":"git"},{"version":"26ec037f9841e49cc5c615deb8e1e73e5beab2ca","lessThan":"e7acfc990c29890c883d0d0ce3f737d003a43b44","status":"affected","versionType":"git"},{"version":"26ec037f9841e49cc5c615deb8e1e73e5beab2ca","lessThan":"a63d2dbaeb50a85d4c976b15a36e6b0c7113db5b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/ipvs/ip_vs_conn.c"],"versions":[{"version":"2.6.36","status":"affected"},{"version":"0","lessThan":"2.6.36","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.36","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.36","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.36","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.36","versionEndExcluding":"6.6.151"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.36","versionEndExcluding":"6.12.103"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.36","versionEndExcluding":"6.18.44"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.36","versionEndExcluding":"7.1.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.36","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/06d1d9b56ef8132fbf85006885eb43d9510b8b02"},{"url":"https://git.kernel.org/stable/c/acbdc276091b308ca7794acb86e761f8203e2f59"},{"url":"https://git.kernel.org/stable/c/300348e3ba1521b003d59825f97e24f9a6859688"},{"url":"https://git.kernel.org/stable/c/44af98cc7d5ef8e730488d5df1eecd5deeaa5947"},{"url":"https://git.kernel.org/stable/c/4649e6faeecdc2d44bfa6ccbe405eef27e55d816"},{"url":"https://git.kernel.org/stable/c/b5ee5b266f833601ac4817f6df0bc496fc376a28"},{"url":"https://git.kernel.org/stable/c/e7acfc990c29890c883d0d0ce3f737d003a43b44"},{"url":"https://git.kernel.org/stable/c/a63d2dbaeb50a85d4c976b15a36e6b0c7113db5b"}],"title":"ipvs: do not propagate one-packet flag to synced conns","x_generator":{"engine":"bippy-1.2.0"}}}}