Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_inner: Fix IPv6 inner_thoff desync
In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset traversing all extension headers, but the result is immediately overwritten with nhoff + sizeof(_ip6h) (40 bytes), which only accounts for the IPv6 base header. This creates a desync between inner_thoff (wrong — points to extension header start) and l4proto (correct — e.g., IPPROTO_TCP), enabling transport header forgery and potential firewall bypass. This issue affects stable versions from Linux 6.2.
For comparison, the normal (non-inner) IPv6 path correctly preserves ipv6_find_hdr()’s result. Removing the incorrect overwrite ensures that ipv6_find_hdr()’s calculated transport header offset is preserved, thereby fixing the desynchronization.
Details
- Affected product:
- AlmaLinux 9.2 ESU , TuxCare 9.6 ESU
- Affected packages:
- kernel @ 5.14.0 (+1 more)
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| AlmaLinux 10 | In Rollout |
4 kernels
|
| AlmaLinux 9 | In Rollout |
94 kernels
|
| Debian 13 | Released |
10 kernels
|
| Oracle Linux 9 | Released |
87 kernels
|
| RHEL 10 | Released |
46 kernels
|
| RHEL 9 | Released |
92 kernels
|
| Rocky Linux 10 | Released |
32 kernels
|
| Rocky Linux 9 | In Rollout |
71 kernels
|
| Ubuntu 24.04 | Planned | — |
| Ubuntu 24.04 AWS | Planned | — |