VulnerabilityReceived
CVE-2026-68476
In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after head reallocation __ip_vs_get_out_rt() calls skb_ensure_writable() which may reallocate skb->head.
CRITICAL 9.8EPSS 0.69%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after head reallocation __ip_vs_get_out_rt() calls skb_ensure_writable() which may reallocate skb->head.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/3fb7edd2018bb1ad0a68157383d9b9dac33dd645
- https://git.kernel.org/stable/c/4f2d1151421520d7ae16ca8d367d0ca09f5dfbd7
- https://git.kernel.org/stable/c/657118cad620172dfd8f6ed5717fd75c0d1f7a5a
- https://git.kernel.org/stable/c/a10f5080afbed242640f2984328de25f84557da1
- https://git.kernel.org/stable/c/a2f57827bf7c695b8c72dc4511cae8e86582369d
- https://git.kernel.org/stable/c/ac6ac3d35bfc0ade9d17d354c84e503a946ebdab
- https://git.kernel.org/stable/c/ad1e14710b360bda087ebf9fb82460eb5ef775de
- https://git.kernel.org/stable/c/e51687fc56c2e39ea6e9532925f1aabd4d529f61
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.