CVE-2026-72319

Source
https://cve.org/CVERecord?id=CVE-2026-72319
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72319.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72319
Downstream
Published
2026-08-15T05:55:32.313Z
Modified
2026-08-18T03:56:41.802341933Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ipvs: ensure inner headers in ICMP errors are in headroom
Details

In the Linux kernel, the following vulnerability has been resolved:

ipvs: ensure inner headers in ICMP errors are in headroom

Sashiko points out that after stripping the outer headers with pskbpull() we should ensure the inner IP headers in ICMP errors from tunnels are present in the skb headroom for functions like ipv4updatepmtu(), icmpsend() and IPVSDBG().

Also, add more checks for the length of the inner headers.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72319.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e
Fixed
19657b3a17b774ae4e2f2635b5ae8638c9344a40
Fixed
dac813101914c21219ac221a60a31a11bc90e7ec
Fixed
dd22f74a09e25ca298ced0a3763ef353242cb78d
Fixed
9bc9b95aee2b2e3f1301a16a67ee504960402875
Fixed
a735f9964a3d9ed97daf9b08507f8b5bcafe6326
Fixed
8f48cfe657409fb5c7ba0521b14da6d47546d9cf
Fixed
92185d6f7819bc558939ae83de7b1abe90e3b5c2
Fixed
3f7a535ff0fa627a0132803e4c2f903ceffcbc1c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72319.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.7.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72319.json"