CVE-2026-97417
HIGH
7,5
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()
The timestamp-only fast path dereferences the option stream as
*(__be32 *)ptr, which assumes 4-byte alignment that the TCP option
stream does not guarantee. Use get_unaligned_be32() instead, which
reads the value safely and already returns host byte order, so the
htonl() on the comparison constant can be dropped.
This matches the existing get_unaligned_be32() use later in the same
function.
https://git.kernel.org/stable/c/4abc1af7ac209c066f4e5dd75cdd56876e5829a9
https://git.kernel.org/stable/c/7ecfa46a536578a7ed335ddf31a854127268c27c
https://git.kernel.org/stable/c/d3bf9eae486490832bd08fd62ab0ac601f346bd4