Bug 2516622 (CVE-2026-72021)
| Summary: | CVE-2026-72021 kernel: ipvs: use parsed transport offset in SCTP state lookup | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the kernel's IP Virtual Server (IPVS) component. This vulnerability occurs when the set_sctp_state() function incorrectly calculates the offset for Stream Control Transmission Protocol (SCTP) chunk headers in IPv6 packets that contain extension headers. A remote attacker could exploit this by sending specially crafted SCTP packets, causing the connection state machine to transition prematurely to an established state. This can lead to incorrect connection tracking, potentially resulting in a denial of service by mismanaging network resources.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-15 06:22:21 UTC
|