Bug 2540479 (CVE-2026-97417) - CVE-2026-97417 kernel: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()
Summary: CVE-2026-97417 kernel: netfilter: nf_conntrack: use get_unaligned_be32() in t...
Keywords:
Status: NEW
Alias: CVE-2026-97417
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-24 16:59 UTC by OSIDB Bzimport
Modified: 2026-09-25 08:37 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-24 16:59:06 UTC
In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()

The timestamp-only fast path dereferences the option stream as
*(__be32 *)ptr, which assumes 4-byte alignment that the TCP option
stream does not guarantee. Use get_unaligned_be32() instead, which
reads the value safely and already returns host byte order, so the
htonl() on the comparison constant can be dropped.

This matches the existing get_unaligned_be32() use later in the same
function.


Note You need to log in before you can comment on or make changes to this bug.