CVE-2026-97417

Source
https://cve.org/CVERecord?id=CVE-2026-97417
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-97417.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-97417
Downstream
AZL (1)
BELL (1)
DEBIAN (1)
RLSA (2)
UBUNTU (1)
Published
2026-09-24T16:03:27Z
Modified
2026-10-05T02:30:52Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()

The timestamp-only fast path dereferences the option stream as *(__be32 *)ptr, which assumes 4-byte alignment that the TCP option stream does not guarantee. Use get_unaligned_be32() instead, which reads the value safely and already returns host byte order, so the htonl() on the comparison constant can be dropped.

This matches the existing get_unaligned_be32() use later in the same function.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97417.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bb9fc37358ffa9de1cc2b2b6f1a559b926ef50d9
Fixed
740ad3d17a281f7764dda4dbeb37cea52e2e31ae
Fixed
a0523267de2523522b0f70972dd1ffa22ec6176c
Fixed
55bcc3376cd7b18954cc9814da697504fdaf12bf
Fixed
0d5ad732e4fdc569eb85861115e8f7b4c2c67852
Fixed
7ecfa46a536578a7ed335ddf31a854127268c27c
Fixed
4abc1af7ac209c066f4e5dd75cdd56876e5829a9
Fixed
d3bf9eae486490832bd08fd62ab0ac601f346bd4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-97417.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.1.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-97417.json"