CVE-2026-97596
In the Linux kernel, the following vulnerability has been resolved:
ipvs: reject invalid states in connection template sync records
IPVS sync receivers validate protocol states before creating or updating a connection. For connection templates, however, they only log states outside the template state range and still store the value in the connection.
A template can be returned by ordinary connection lookup. TCP and SCTP then use the invalid state as an index into their transition tables.
Reject invalid template states in both sync protocol versions before looking up or modifying a connection. The version 1 path handles both IPv4 and IPv6 records.
CVSS
NVD hasn't assigned a CVSS score to this CVE (common since the April 2026 policy change).
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.21%
- Percentile among all scored CVEs: 10
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
References
- https://git.kernel.org/stable/c/0c61f7d8e18a978aec2a16d9acd5f682f1c72476
- https://git.kernel.org/stable/c/1a8f15911352bb3cf4663aa02049c49c7f30e524
- https://git.kernel.org/stable/c/50c3f06222eafe9cca7ca51a0ef83311d7cab353
- https://git.kernel.org/stable/c/5677e81ffdbfc1c03dcb427fb8b1c38289bed76d
- https://git.kernel.org/stable/c/652d9caa5ac925ab012834e325d77b9ed638d4fc
- https://git.kernel.org/stable/c/74cb39735b6cd0aff4b5584158f09376fd97aadf
- https://git.kernel.org/stable/c/d4eb339b442a0ffaa565779b975494a0a0664f18
- https://git.kernel.org/stable/c/fc10dc4511e6e2e2b4098ee115c8e5639471f23d
Raw JSON (NVD)
Show
{
"id": "CVE-2026-97596",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "275411430f892407b885be1de2548b2e632892c3",
"lessThan": "5677e81ffdbfc1c03dcb427fb8b1c38289bed76d",
"versionType": "git"
},
{
"status": "affected",
"version": "275411430f892407b885be1de2548b2e632892c3",
"lessThan": "d4eb339b442a0ffaa565779b975494a0a0664f18",
"versionType": "git"
},
{
"status": "affected",
"version": "275411430f892407b885be1de2548b2e632892c3",
"lessThan": "1a8f15911352bb3cf4663aa02049c49c7f30e524",
"versionType": "git"
},
{
"status": "affected",
"version": "275411430f892407b885be1de2548b2e632892c3",
"lessThan": "652d9caa5ac925ab012834e325d77b9ed638d4fc",
"versionType": "git"
},
{
"status": "affected",
"version": "275411430f892407b885be1de2548b2e632892c3",
"lessThan": "fc10dc4511e6e2e2b4098ee115c8e5639471f23d",
"versionType": "git"
},
{
"status": "affected",
"version": "275411430f892407b885be1de2548b2e632892c3",
"lessThan": "50c3f06222eafe9cca7ca51a0ef83311d7cab353",
"versionType": "git"
},
{
"status": "affected",
"version": "275411430f892407b885be1de2548b2e632892c3",
"lessThan": "0c61f7d8e18a978aec2a16d9acd5f682f1c72476",
"versionType": "git"
},
{
"status": "affected",
"version": "275411430f892407b885be1de2548b2e632892c3",
"lessThan": "74cb39735b6cd0aff4b5584158f09376fd97aadf",
"versionType": "git"
}
],
"programFiles": [
"net/netfilter/ipvs/ip_vs_sync.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/netfilter/ipvs/ip_vs_sync.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:10.907",
"references": [
{
"url": "https://git.kernel.org/stable/c/0c61f7d8e18a978aec2a16d9acd5f682f1c72476",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1a8f15911352bb3cf4663aa02049c49c7f30e524",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/50c3f06222eafe9cca7ca51a0ef83311d7cab353",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5677e81ffdbfc1c03dcb427fb8b1c38289bed76d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/652d9caa5ac925ab012834e325d77b9ed638d4fc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/74cb39735b6cd0aff4b5584158f09376fd97aadf",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d4eb339b442a0ffaa565779b975494a0a0664f18",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fc10dc4511e6e2e2b4098ee115c8e5639471f23d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: reject invalid states in connection template sync records\n\nIPVS sync receivers validate protocol states before creating or updating a\nconnection. For connection templates, however, they only log states outside\nthe template state range and still store the value in the connection.\n\nA template can be returned by ordinary connection lookup. TCP and SCTP then\nuse the invalid state as an index into their transition tables.\n\nReject invalid template states in both sync protocol versions before\nlooking up or modifying a connection. The version 1 path handles both\nIPv4 and IPv6 records."
}
],
"lastModified": "2026-10-03T11:18:06.110",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}