Junglewise Threat Intelligence

CVE-2026-74669: Linux kernel ipvs stack out-of-bounds write in ICMP handling

CVE-2026-74669 · Severity: critical · CVSS 9.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's IP Virtual Server (IPVS) component, used for load balancing and network traffic management, contains a stack memory corruption vulnerability in its ICMP error handling path. When processing ICMP error messages from tunneled packets, the component fails to clear stale IPv4 option metadata, allowing an attacker to trigger an out-of-bounds write to kernel stack memory. This can lead to privilege escalation, denial of service, or complete system compromise.

Technical details

The vulnerability is a stack out-of-bounds write in the IPVS ICMP handling function ip_vs_in_icmp(). When rebasing a socket buffer from an outer ICMP packet to the quoted original request, the function fails to clear the IPCB(skb)->opt metadata that still describes the outer IPv4 header. If the outer header contains a timestamp option, its stale offset can point into the quoted transport header after the rebase. The __ip_options_echo() function then treats a byte at that stale location as the option length and copies it into fixed-size stack storage in __icmp_send(), causing an out-of-bounds write. The fix clears the IPv4 option metadata via memset() after calling skb_reset_network_header(). No authentication or user interaction is required; the vulnerability is triggered by network-layer processing of crafted ICMP packets.

Affected products

  • Linux Linux kernel Linux 2.6.11 through 6.18 and likely earlier versions (introduced by commit f2edb9f7706d)

Timeline

  • 2026-08-22: disclosed: CVE-2026-74669 published
  • 2026-08-19: patched: Fix committed by Greg Kroah-Hartman to stable kernel trees

References

Related threats