Bug 2541208 (CVE-2026-97596) - CVE-2026-97596 kernel: ipvs: reject invalid states in connection template sync records
Summary: CVE-2026-97596 kernel: ipvs: reject invalid states in connection template syn...
Keywords:
Status: NEW
Alias: CVE-2026-97596
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 11:01 UTC by OSIDB Bzimport
Modified: 2026-09-29 11:18 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 11:01:55 UTC
In the Linux kernel, the following vulnerability has been resolved:

ipvs: reject invalid states in connection template sync records

IPVS sync receivers validate protocol states before creating or updating a
connection. For connection templates, however, they only log states outside
the template state range and still store the value in the connection.

A template can be returned by ordinary connection lookup. TCP and SCTP then
use the invalid state as an index into their transition tables.

Reject invalid template states in both sync protocol versions before
looking up or modifying a connection. The version 1 path handles both
IPv4 and IPv6 records.


Note You need to log in before you can comment on or make changes to this bug.