CVE-2026-97596

Source
https://cve.org/CVERecord?id=CVE-2026-97596
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97596.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97596
Downstream
Published
2026-09-25T10:22:11Z
Modified
2026-09-26T03:48:36Z
Summary
ipvs: reject invalid states in connection template sync records
Details

In the Linux kernel, the following vulnerability has been resolved:

ipvs: reject invalid states in connection template sync records

IPVS sync receivers validate protocol states before creating or updating a connection. For connection templates, however, they only log states outside the template state range and still store the value in the connection.

A template can be returned by ordinary connection lookup. TCP and SCTP then use the invalid state as an index into their transition tables.

Reject invalid template states in both sync protocol versions before looking up or modifying a connection. The version 1 path handles both IPv4 and IPv6 records.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97596.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
275411430f892407b885be1de2548b2e632892c3
Fixed
fc10dc4511e6e2e2b4098ee115c8e5639471f23d
Fixed
50c3f06222eafe9cca7ca51a0ef83311d7cab353
Fixed
0c61f7d8e18a978aec2a16d9acd5f682f1c72476
Fixed
74cb39735b6cd0aff4b5584158f09376fd97aadf

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97596.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.19.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97596.json"