Kernel memory access via truncated tunneled ICMP errors
Published Aug 15, 2026 · Updated Aug 15, 2026
Out-of-bounds access in Linux IPVS allows remote attackers to access invalid kernel memory via tunneled ICMP errors. ip_vs_in_icmp() strips outer headers with pskb_pull() but passes inner headers to ipv4_update_pmtu(), icmp_send(), and debug paths without first pulling their full lengths into linear skb headroom. Reachability requires IPVS tunnel forwarding and a crafted ICMP error containing a truncated or non-linear quoted packet; the published record does not establish a specific post-access consequence.
Summary
What happened
Out-of-bounds access in Linux IPVS allows remote attackers to access invalid kernel memory via tunneled ICMP errors. ip_vs_in_icmp() strips outer headers with pskb_pull() but passes inner headers to ipv4_update_pmtu(), icmp_send(), and debug paths without first pulling their full lengths into linear skb headroom. Reachability requires IPVS tunnel forwarding and a crafted ICMP error containing a truncated or non-linear quoted packet; the published record does not establish a specific post-access consequence.
The record
- CVE
- CVE-2026-72319
- Published
- Aug 15, 2026
- Updated
- Aug 15, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- T1190
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 15, 2026CVE publishedPublication date reported by the CVE source.
- Aug 15, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=3.7
- Affected versionversion=f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e <19657b3a17b774ae4e2f2635b5ae8638c9344a40
- Affected versionversion=f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e <3f7a535ff0fa627a0132803e4c2f903ceffcbc1c
- Affected versionversion=f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e <8f48cfe657409fb5c7ba0521b14da6d47546d9cf
- Affected versionversion=f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e <92185d6f7819bc558939ae83de7b1abe90e3b5c2
- Affected versionversion=f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e <9bc9b95aee2b2e3f1301a16a67ee504960402875
- Affected versionversion=f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e <a735f9964a3d9ed97daf9b08507f8b5bcafe6326
- Affected versionversion=f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e <dac813101914c21219ac221a60a31a11bc90e7ec
- Affected versionversion=f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e <dd22f74a09e25ca298ced0a3763ef353242cb78d
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo