<Vulnerability name="CVE-2026-72348">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-08-15T00:00:00</PublicDate>
    <Bugzilla id="2516348" url="https://bugzilla.redhat.com/show_bug.cgi?id=2516348" xml:lang="en:us">
kernel: netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-130</CWE>
    <Details xml:lang="en:us" source="Mitre">
In the Linux kernel, the following vulnerability has been resolved:

netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop

The ah, hbh and rt matches check that the fixed extension header is
present, then use the header length field to derive the advertised
extension header length for matching.

For the ah match, add the missing advertised-length check. For hbh
and rt, update the existing advertised-length checks. In all three
cases, set hotdrop to true before returning false when the advertised
extension header length exceeds the available skb data.

Returning false treats the packet as a rule mismatch. Set hotdrop to
true and drop malformed packets so they cannot bypass rules intended
to drop packets with these IPv6 extension headers.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the Linux kernel's netfilter subsystem, specifically within ip6tables. A remote attacker could send specially crafted IPv6 packets with malformed extension headers. Due to improper length checks, these malformed packets might not be correctly identified and dropped by ip6tables rules. This could allow an attacker to bypass intended security filtering policies.
    </Details>
    <Statement xml:lang="en:us">
The IPv6 iptables AH, Hop-by-Hop (HBH), and Routing Header (RT) matches use extension-header length fields when evaluating packets. When a malformed IPv6 packet advertises an extension-header length larger than the data actually available in the skb, the affected match functions can return `false` without setting `hotdrop`. Netfilter therefore treats the malformed header as a normal rule mismatch rather than an invalid packet that must be dropped. As a result, specially crafted packets may bypass ip6tables rules intended to match and drop traffic containing these IPv6 extension headers.

The vulnerable path is remotely reachable when an affected IPv6 traffic path is exposed, and no local account, local code execution, authentication, or user interaction is required. For CVSS, `AV:N/AC:L/PR:N/UI:N` therefore reflects the remote unauthenticated attack surface. Exploitation is limited to systems using relevant ip6tables AH, HBH, or RT extension-header match rules.

The flaw does not itself cause an out-of-bounds memory access, kernel memory corruption, information disclosure, or denial of service. Its direct security impact is a firewall policy bypass. `I:L` reflects the ability to circumvent an administrator-defined packet-filtering decision. Any additional confidentiality or integrity impact depends on the services and security boundaries protected by the bypassed firewall rule rather than being a direct consequence of the kernel flaw. A paranoid assessment may therefore consider limited confidentiality and integrity impact if traffic that should have been blocked can reach otherwise protected services.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>kernel</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>kernel</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>kernel</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>kernel-rt</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>kernel</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>kernel-rt</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>kernel</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>kernel-rt</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-72348
https://nvd.nist.gov/vuln/detail/CVE-2026-72348
https://lore.kernel.org/linux-cve-announce/2026081511-CVE-2026-72348-e6e6@gregkh/T
    </References>
</Vulnerability>