netfilter: flowtable: use dst in this direction when pushing IPIP header
Published Aug 15, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.55%
Description
When pushing the IPIP header, the route of the other direction is used to calculate the headroom, use the route in this direction. Accessing the other tuple to set the IP source and destination is fine because this tuple does not provide such information to avoid storing redundant information. However, this tuple already provides the dst for this direction, this went unnoticed because this bug affects headroom and iph->frag_off only at this stage.
Affected products
-
Affected
- ≥ , <
- ≥ , <
-
Affected
- 6.19
Unaffected
- ≥ 0, < 6.19
- ≥ 7.1.5, ≤ 7.1.*
- 7.2
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-72249 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2516381 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-59148 Advisory
- https://git.kernel.org/stable/c/c328b90c17fc5fa7786503695152880b2afb9326
- https://git.kernel.org/stable/c/ecb78fbb03d3f86e2e93767875e273308086a424
- https://lore.kernel.org/linux-cve-announce/2026081552-CVE-2026-72249-ac76@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-72249
- https://www.cve.org/CVERecord?id=CVE-2026-72249
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data