CVE-2026-46244

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/06/2026
Last modified:
22/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> netfilter: nft_inner: Fix IPv6 inner_thoff desync<br /> <br /> In nft_inner_parse_l2l3(), when processing inner IPv6 packets,<br /> ipv6_find_hdr() correctly computes the transport header offset<br /> traversing all extension headers, but the result is immediately<br /> overwritten with nhoff + sizeof(_ip6h) (40 bytes), which only<br /> accounts for the IPv6 base header. This creates a desync between<br /> inner_thoff (wrong — points to extension header start) and l4proto<br /> (correct — e.g., IPPROTO_TCP), enabling transport header forgery<br /> and potential firewall bypass. This issue affects stable versions<br /> from Linux 6.2.<br /> <br /> For comparison, the normal (non-inner) IPv6 path correctly<br /> preserves ipv6_find_hdr()&amp;#39;s result. Removing the incorrect overwrite<br /> ensures that ipv6_find_hdr()&amp;#39;s calculated transport header offset is<br /> preserved, thereby fixing the desynchronization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.142 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.92 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.34 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.11 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*