KernelScan.io

CRITICAL Introduced in 2.6.12

netfilter ip6tables ExtHdr Bypass

CVE-2026-72348

CVSS 9.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop The ah, hbh and rt matches check that the fixed extension header is present, then use the header length field to derive the advertised extension header length for matching. For the ah match, add the missing advertised-length check. For hbh and rt, update the existing advertised-length checks. In all three cases, set hotdrop to true before returning false when the advertised extension header length exceeds the available skb data. Returning false treats the packet as a rule mismatch. Set hotdrop to true and drop malformed packets so they cannot bypass rules intended to drop packets with these IPv6 extension headers.

02

Engine v0.6.0

Risk summary

Malformed IPv6 extension headers with an advertised length exceeding the actual packet data can bypass ip6tables firewall rules that match on AH, Hop-by-Hop, or Routing headers. An attacker can craft packets that slip past rules intended to drop or filter traffic based on these extension headers, weakening firewall enforcement on IPv6-enabled hosts.

Affectednet/ipv6/netfilter/ip6t_ah.c, net/ipv6/netfilter/ip6t_hbh.c, net/ipv6/netfilter/ip6t_rt.c (netfilter ip6tables)

Vulnerability analysis

The IPv6 netfilter extension header matches for AH, Hop-by-Hop, and Routing headers check that the fixed header is present and then derive the advertised length from a header field. When the advertised length exceeds the remaining packet data, the match reports a rule mismatch without marking the packet for drop. A mismatch result tells the firewall the rule did not apply, so a rule intended to drop packets carrying these extension headers is skipped and the malformed packet continues through the firewall table. The fix marks malformed packets for immediate drop before reporting a mismatch and adds the missing length check for the AH match, ensuring malformed extension headers are dropped rather than treated as non-matching. The vulnerable path is reached when processing incoming IPv6 packets on a host with ip6tables rules using these extension header matches, requiring no special privileges from the attacker.

03

BranchIntroducedFixed inPatch commit
6.62.6.126.6.1452fd89a50a978
6.122.6.126.12.973578b6d92a5b
6.182.6.126.18.403d441be2b1c5
mainline2.6.127.2-rc343ccc20b5a73
6.12.6.126.1.178f775fcf384b0
5.152.6.125.15.212fc416870100c
7.12.6.127.1.5d5e39e5eb6b3
5.102.6.125.10.261f16d856b6af5