Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-97596

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ipvs: reject invalid states in connection template sync records<br /> <br /> IPVS sync receivers validate protocol states before creating or updating a<br /> connection. For connection templates, however, they only log states outside<br /> the template state range and still store the value in the connection.<br /> <br /> A template can be returned by ordinary connection lookup. TCP and SCTP then<br /> use the invalid state as an index into their transition tables.<br /> <br /> Reject invalid template states in both sync protocol versions before<br /> looking up or modifying a connection. The version 1 path handles both<br /> IPv4 and IPv6 records.

Impacto