CRITICAL Introduced in 2.6.39
ipvs SyncSeq Leak
CVE-2026-98078
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
01Description
In the Linux kernel, the following vulnerability has been resolved: ipvs: fix reversed sequence option serialization hton_seq() expects the host-order source first and the unaligned network-order destination second. The version 1 sync sender passes these arguments in reverse for both sequence blocks. This leaves 24 bytes of the kmalloc-backed message unwritten. It may disclose stale heap data and replace the live connection sequence state with values read from the buffer. Pass the connection sequence state as the source and the message payload as the destination for both blocks.
02KernelScan AI Analysis
Risk summary
An attacker who can send traffic to a service behind an IPVS load balancer with sync enabled can trigger disclosure of 24 bytes of stale kernel heap data in sync messages sent to peer nodes, and simultaneously corrupt the sequence-tracking state of the connection being synced. No privileges are required beyond network access to the load-balanced service.
Vulnerability analysis
When the IPVS sync daemon serializes connection sequence state into version 1 sync messages, the source and destination arguments for the byte-order conversion are swapped. The allocated message buffer is treated as the source and the live connection state as the destination. This leaves part of the freshly allocated sync message uninitialized, so stale kernel heap data is transmitted to sync peers, while the connection's own sequence-tracking state is overwritten with whatever values were left in the buffer. The fix corrects the argument order so the connection state is properly copied into the message and the buffer is fully initialized before transmission. The vulnerable path is reached when IPVS load balancing is configured with sync enabled and a connection using sequence tracking is established; an external network attacker can trigger it by connecting to a service behind the IPVS load balancer with no special privileges.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 2.6.39 | 6.12.111 | e1c9f9446d3e |
| 6.18 | 2.6.39 | 6.18.53 | 524599714558 |
| 7.2 | 2.6.39 | 7.2.7 | de6cc6ec7932 |
| mainline | 2.6.39 | 7.3-rc3 | b04578b74f2d |