GHSA-86rv-j9hx-pv73HighCVSS 7.5
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: use...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()
The timestamp-only fast path dereferences the option stream as *(__be32 *)ptr, which assumes 4-byte alignment that the TCP option stream does not guarantee. Use get_unaligned_be32() instead, which reads the value safely and already returns host byte order, so the htonl() on the comparison constant can be dropped.
This matches the existing get_unaligned_be32() use later in the same function.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-97417
- https://git.kernel.org/stable/c/4abc1af7ac209c066f4e5dd75cdd56876e5829a9
- https://git.kernel.org/stable/c/7ecfa46a536578a7ed335ddf31a854127268c27c
- https://git.kernel.org/stable/c/d3bf9eae486490832bd08fd62ab0ac601f346bd4
- https://git.kernel.org/stable/c/0d5ad732e4fdc569eb85861115e8f7b4c2c67852
- https://git.kernel.org/stable/c/55bcc3376cd7b18954cc9814da697504fdaf12bf
- https://git.kernel.org/stable/c/740ad3d17a281f7764dda4dbeb37cea52e2e31ae
- https://git.kernel.org/stable/c/a0523267de2523522b0f70972dd1ffa22ec6176c
- https://github.com/advisories/GHSA-86rv-j9hx-pv73