CVE-2026-46244: critical vulnerability in Linux
netfilter: nft_inner: Fix IPv6 inner_thoff desync
Published · Updated
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.1epss 0.5%
exploitation probability
0.5%top 62% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_inner: Fix IPv6 inner_thoff desync
In nft_inner_parse_l2l3(), when processing inner IPv6 packets,
ipv6_find_hdr() correctly computes the transport header offset
traversing all extension headers, but the result is immediately
overwritten with nhoff + sizeof(_ip6h) (40 bytes), which only
accounts for the IPv6 base header. This creates a desync between
inner_thoff (wrong — points to extension header start) and l4proto
(correct — e.g., IPPROTO_TCP), enabling transport header forgery
and potential firewall bypass. This issue affects stable versions
from Linux 6.2.
For comparison, the normal (non-inner) IPv6 path correctly
preserves ipv6_find_hdr()'s result. Removing the incorrect overwrite
ensures that ipv6_find_hdr()'s calculated transport header offset is
preserved, thereby fixing the desynchronization.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Linux · LinuxRelated CVEs — Linux
In the same product, most dangerous first.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
References
https://access.redhat.com/errata/RHSA-2026:33215https://access.redhat.com/errata/RHSA-2026:34094https://access.redhat.com/errata/RHSA-2026:34443https://access.redhat.com/errata/RHSA-2026:34911https://access.redhat.com/errata/RHSA-2026:36018https://access.redhat.com/errata/RHSA-2026:55618https://access.redhat.com/errata/RHSA-2026:55763https://access.redhat.com/errata/RHSA-2026:56225https://access.redhat.com/security/cve/CVE-2026-46244https://bugzilla.redhat.com/show_bug.cgi?id=2484451https://git.kernel.org/stable/c/689bbf48c1f45130086ae1c46ab83ea4c753c601https://git.kernel.org/stable/c/870d59e2cf218e7418491e26bad768cb16654582