CVE-2026-52915
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/06/2026
Última modificación:
08/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
netfilter: ip6t_hbh: reject oversized option lists<br />
<br />
struct ip6t_opts stores at most IP6T_OPTS_OPTSNR option descriptors,<br />
but hbh_mt6_check() does not reject larger optsnr values supplied from<br />
userspace.<br />
<br />
Validate optsnr in the rule setup path so only match data that fits the<br />
fixed-size opts array can be installed. This follows the existing xtables<br />
pattern of rejecting invalid user-provided counts in checkentry() and<br />
keeps the packet matching path unchanged.<br />
<br />
`struct ip6t_opts` has a fixed `opts[IP6T_OPTS_OPTSNR]` array,<br />
where `IP6T_OPTS_OPTSNR` is 16, then off-by-one array access is possible:<br />
<br />
[ 137.924693][ T8692] UBSAN: array-index-out-of-bounds in ../net/ipv6/netfilter/ip6t_hbh.c:110:29<br />
[ 137.926167][ T8692] index 16 is out of range for type &#39;__u16 [16]&#39;
Impacto
Puntuación base 3.x
7.10
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 2.6.12.1 (incluyendo) | 5.10.258 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (incluyendo) | 5.15.209 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (incluyendo) | 6.1.175 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (incluyendo) | 6.6.142 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (incluyendo) | 6.12.92 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.34 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.11 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/2d523ba48d4ecc46acfb6aba548292cfcce1ac02
- https://git.kernel.org/stable/c/41ec2e242f1702e8370ddfe14d22b7a766021c3e
- https://git.kernel.org/stable/c/4322dcde6b4173c2d8e8e6118ed290794263bcc8
- https://git.kernel.org/stable/c/57b0ac5e1b46f1f0338dff392ef2092e2871b412
- https://git.kernel.org/stable/c/588933f1a2ca5ff99274f8c9f25dc3a25d0191c3
- https://git.kernel.org/stable/c/6feb43c0995ab3a9c826707eb46541a1696fe4f7
- https://git.kernel.org/stable/c/784aadea7a108c9f90985683caa87fb0198c6a39
- https://git.kernel.org/stable/c/db0250470f023f159094052c0bd5ab026a88ae93



