OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97417

HIGH · CVSS 7.5 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's netfilter component, specifically in the TCP selective acknowledgment (SACK) handling, where improper dereferencing of a potentially misaligned option stream can lead to undefined behavior. This could result in stability issues or potential exploitation, making it critical for organizations using affected Linux distributions to prioritize patching. System administrators and security teams managing Linux environments should address this vulnerability to ensure the integrity and reliability of their network traffic handling.

CVE
CVE-2026-97417
Severity
HIGH
CVSS
7.5
EPSS
0.49%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() The timestamp-only fast path dereferences the option stream as *(__be32 *)ptr, which assumes 4-byte alignment that the TCP option stream does not guarantee. Use get_unaligned_be32() instead, which reads the value safely and already returns host byte order, so the htonl() on the comparison constant can be dropped. This matches the existing get_unaligned_be32() use later in the same function.