Linux Kernel Vulnerability in IPVS Connection Management
CVE-2026-80714
What is CVE-2026-80714?
A vulnerability in the Linux kernel's IP Virtual Server (IPVS) module could allow synced connections to improperly inherit flags from destination connections, leading to potential issues in connection management. Specifically, when IP_VS_CONN_F_ONE_PACKET connections are incorrectly synchronized, it can create stale hash nodes pointing to freed structures, causing unintended data exposure and connection handling errors. The resolution involves ensuring that this flag is dropped upon binding synced connections to prevent such inconsistencies.
Affected Version(s)
Linux 26ec037f9841e49cc5c615deb8e1e73e5beab2ca < 06d1d9b56ef8132fbf85006885eb43d9510b8b02
Linux 26ec037f9841e49cc5c615deb8e1e73e5beab2ca
Linux 26ec037f9841e49cc5c615deb8e1e73e5beab2ca < 300348e3ba1521b003d59825f97e24f9a6859688