Executive brief
The Linux kernel's netfilter firewall component failed to properly validate malformed IPv6 extension headers (AH, HBH, and RT), allowing attackers to send crafted packets that bypass packet filtering rules designed to block specific header types. This creates a potential for unauthorized traffic to pass through firewalls and reach protected systems.
Technical details
A validation logic flaw exists in the ip6tables netfilter code (files ip6t_ah.c, ip6t_hbh.c, and ip6t_rt.c) where advertised IPv6 extension header lengths are not properly checked against actual available packet data. When a malformed packet contains an advertised header length that exceeds the available socket buffer (skb) data, the code returns false (treating it as a rule mismatch) without setting the hotdrop flag, allowing the packet to bypass filtering rules. The fix adds the missing length validation for AH headers and updates existing checks for HBH and RT headers, ensuring that malformed packets are dropped (hotdrop = true) rather than treated as non-matching. The vulnerability affects all Linux kernel versions since 2.6.12-rc2 and is reachable by any network attacker sending malformed IPv6 packets.
Affected products
- Linux Linux kernel all versions since 2.6.12-rc2
Timeline
- 2026-08-15: disclosed
- 2026-07-24: patched