In the Linux kernel, the following vulnerability has been resolved:
ipvs: clear IPv4 options after rebasing tunnel ICMP errors
ipvsinicmp() rebases an skb from the outer ICMP packet to the quoted original request before passing it to icmpsend(). However, IPCB(skb)->opt still describes the outer IPv4 header.
A timestamp option in the outer header can therefore leave an offset that points into the quoted transport header after the rebase. __ipoptionsecho() treats a byte at that stale location as the option length and copies it into the fixed-size option storage on the _icmpsend() stack, causing a stack out-of-bounds write.
Clear the stale option metadata after resetting the network header. Keep the remaining control block fields, including the ingress interface used by the ICMP response path.