CVE-2026-68477

Source
https://cve.org/CVERecord?id=CVE-2026-68477
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68477.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68477
Downstream
Published
2026-08-15T05:51:32.820Z
Modified
2026-08-16T03:48:30.309770309Z
Summary
ipvs: fix more places with wrong ipv6 transport offsets
Details

In the Linux kernel, the following vulnerability has been resolved:

ipvs: fix more places with wrong ipv6 transport offsets

Sashiko reports for more incorrect IPv6 transport offsets.

The app code for TCP was assuming IPv4 network header even after the ipvsh argument was provided. This can cause problems with apps over IPv6. As for the only official app in the kernel tree (FTP) this problem is harmless because we use Netfilter to mangle the FTP ports and we do not adjust the TCP seq numbers.

Also, provide correct offset of the ICMPV6 header in ipvsouticmpv6() for correct checksum checks when the IPv6 packet has extension headers.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68477.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2a3b791e6e1169f374224d164738e9f7be703d77
Fixed
613ce63711b8d431bba90781f133c39a21684f87
Fixed
95d4511d81b2b37e5d2bdde5d912e48243eae517
Fixed
3a9dc9b55b53d94613a587604b77d3b20024090c
Fixed
a3f0d5b605cd5da5c95279969fb8cea4e55cee5b
Fixed
7350eb7ead172ae8024897d4b0f2e15c5318279c
Fixed
d4ec18f48ce78a3bf7c999ac908691007375fe99
Fixed
905d7a363ade96a19f214815361e11981142c547
Fixed
b3fe4cbd583895987935a9bdad01c8f9d3a02310

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68477.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.28
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68477.json"