PT-2026-46007 · Linux+2 · Linux Kernel+2

·

CVE-2026-46244

·

Published

2026-05-12

·

Updated

2026-07-28

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions 6.2 and later
Description A desynchronization issue exists in the nft inner parse l2l3() function when processing inner IPv6 packets. While the ipv6 find hdr() function correctly calculates the transport header offset by traversing extension headers, this value is incorrectly overwritten by a calculation that only accounts for the IPv6 base header. This results in a mismatch between inner thoff, which incorrectly points to the start of the extension header, and l4proto, which correctly identifies the protocol (e.g., IPPROTO TCP). This discrepancy allows for transport header forgery and potential firewall bypass.
Recommendations Update to a version where the incorrect overwrite in the nft inner parse l2l3() function has been removed to ensure the transport header offset is preserved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:34911
ALSA-2026:36018
BDU:2026-08901
CVE-2026-46244
OESA-2026-2869
OESA-2026-3157
OPENSUSE-SU-2026:11014-1
OPENSUSE-SU-2026:21388-1
RHSA-2026:34094
RHSA-2026:34443
RHSA-2026:34911
SUSE-SU-2026:22433-1
SUSE-SU-2026:22436-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:22460-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:2722-1
SUSE-SU-2026:2799-1
USN-8488-1
USN-8488-2
USN-8489-1
USN-8490-1
USN-8490-2
USN-8491-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8507-1
USN-8508-1
USN-8545-1
USN-8546-1
USN-8569-1
USN-8603-1
USN-8604-1
USN-8605-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8619-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux