Stack Out-of-Bounds Read Vulnerability in Linux Kernel Affects IPTFS Policies
CVE-2026-68420
What is CVE-2026-68420?
A vulnerability has been identified in the Linux kernel that allows for a stack out-of-bounds read when specific outbound policies are in use with optional IPTFS templates. This issue arises due to the improper handling of these templates, potentially allowing attackers to read sensitive information from kernel memory. In response to reports, recent updates have extended the checks to disallow optional IPTFS in outbound policies, ensuring they are treated in the same way as tunnel mode templates. The vulnerability specifically affects outbound networking and does not impact inbound or forwarding policies.
Affected Version(s)
Linux d1716d5a44c37e5743bf6ea4e5cdbdab37727f27
Linux d1716d5a44c37e5743bf6ea4e5cdbdab37727f27 < 9333f4b6f44858fc98eb12bf26b8d2959eb975d5
Linux d1716d5a44c37e5743bf6ea4e5cdbdab37727f27