HIGH Introduced in 3.1
netfilter TcpSack Deref
CVE-2026-97417
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
KernelScan AI7.5HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() The timestamp-only fast path dereferences the option stream as *(__be32 *)ptr, which assumes 4-byte alignment that the TCP option stream does not guarantee. Use get_unaligned_be32() instead, which reads the value safely and already returns host byte order, so the htonl() on the comparison constant can be dropped. This matches the existing get_unaligned_be32() use later in the same function.
02KernelScan AI Analysis
Risk summary
A remote, unauthenticated attacker can send a crafted TCP packet to any host with connection tracking enabled, triggering an unaligned memory access in the TCP option fast path. On architectures that enforce alignment (ARM, MIPS, SPARC), this causes a kernel panic, resulting in a denial of service. x86 and ARM64 with hardware unaligned support are typically unaffected beyond a minor performance cost.
Vulnerability analysis
The connection tracking subsystem's TCP option parser has a fast path that dereferences option bytes as a 4-byte-aligned value, but TCP option data in a packet buffer does not guarantee that alignment. On architectures that require aligned memory access, this triggers a fault that panics the kernel; on tolerant architectures it is benign. The fix replaces the direct cast-and-dereference with a safe unaligned read helper that performs the access byte-by-byte. Any TCP packet reaching a host with connection tracking active can enter this path — the attacker needs only network reachability, no authentication or local access.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 3.1 | 6.12.111 | 7ecfa46a5365 |
| 6.18 | 3.1 | 6.18.53 | 4abc1af7ac20 |
| mainline | 3.1 | 7.2 | d3bf9eae4864 |