CVE-2026-72020

Source
https://cve.org/CVERecord?id=CVE-2026-72020
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72020.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72020
Downstream
Published
2026-08-15T05:51:46.675Z
Modified
2026-08-16T03:48:30.994868829Z
Summary
ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
Details

In the Linux kernel, the following vulnerability has been resolved:

ipvs: reset full ipvsseq structs in ipvsconn_new

Commit 9a05475cebdd ("ipvs: avoid kmemcachezalloc in ipvsconnnew") changed ipvsconnnew() to allocate an ipvsconn object with kmemcachealloc(). The function then initializes many fields explicitly, but only resets inseq.delta and outseq.delta in the two struct ipvsseq members.

That leaves initseq and previousdelta uninitialized. This is normally harmless while the corresponding IPVSCONNFINSEQ or IPVSCONNFOUTSEQ flag is clear. For connections learned from a sync message, however, ipvsprocconn() preserves those flags from IPVSCONNFBACKUPMASK and passes opt=NULL when the message omits IPVSOPTSEQDATA. In that case the new connection can be hashed with SEQ flags set but with the rest of inseq/out_seq still containing stale slab data.

When a packet for such a connection is later handled by an IPVS application helper, vsfixseq() and vsfixackseq() use previousdelta and init_seq to rewrite TCP sequence numbers. A malformed sync message can therefore make forwarded packets carry stale slab bytes in their TCP seq/ack numbers, and can also corrupt the forwarded TCP flow.

Reset both struct ipvsseq members completely before publishing the connection. This matches the existing "reset struct ipvsseq" comment and keeps the sequence-adjustment gates inactive unless valid sequence data is installed later.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72020.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9a05475cebdd6341884b5901e53870be26e65158
Fixed
3bf9a260188b2a5449cbddc032a749ab433fe328
Fixed
6378c5cb360eb1750f88839d7c3613ea92ac1816
Fixed
32c299e28b8eea6cbbd23b97dc61401e9ef9c445
Fixed
9e36602cbec552286f7e691cfd366525c565ee74
Fixed
d0eed7177e822cab83141e5c44b2aa345c7fd379
Fixed
83fb4c2c5344f02eac929f66de3c9d1adfcde04c
Fixed
6335ab62d5fc9ed875279238233fba3462c168f5
Fixed
2975324d164c552b028632f107b567302863b7f6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72020.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.10.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72020.json"