CVE-2026-72248

Source
https://cve.org/CVERecord?id=CVE-2026-72248
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72248.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72248
Downstream
Published
2026-08-15T05:54:36Z
Modified
2026-08-18T03:56:22Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
netfilter: flowtable: support IPIP tunnel with direct xmit
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: support IPIP tunnel with direct xmit

The combination of IPIP tunnel with direct xmit, eg. bridge device, breaks because no dst_entry is provided to check the skb headroom and to set the iph->frag_off field. This leads to invalid dst usage and can trigger a crash in the tunnel transmit path.

Fix this by moving dst_cache and dst_cookie out of the runtime union so that they can be shared by neighbour, xfrm, and direct tunnel flows. For FLOW_OFFLOAD_XMIT_DIRECT tuples carrying tunnel metadata, preserve route state in these shared fields and release it through the common dst release path.

Since dst_entry is now available to the three supported xmit modes and dst_release() already deals with NULL dst, remove the xmit type check in nft_flow_dst_release(). Moreover, skip the check if the dst entry is NULL in nf_flow_dst_check() which is now the case for the direct xmit case.

Based on patch from Rein Wei n05ec@lzu.edu.cn.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72248.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d30301ba4b07ac92eb38353a111833b009003170
Fixed
0880c4ed122d0cddc9f29a2b28f055d1f24f0fca
Fixed
fa7395c02d95e51bad2952325d2d6503bfbad437

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72248.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72248.json"