In the Linux kernel, the following vulnerability has been resolved:
gue: validate REMCSUM private option length
GUE private flags can indicate that remote checksum offload metadata is
present. The private flags field itself is accounted for by
guehdr_flags_len(), but guehdr_priv_flags_len() currently returns 0 even
when GUE_PFLAG_REMCSUM is set.
This lets a packet with only the private flags field pass
validate_gue_flags(), after which gue_remcsum() and gue_gro_remcsum()
read the missing REMCSUM start/offset fields from the following bytes.
Account for GUE_PLEN_REMCSUM when GUE_PFLAG_REMCSUM is present so that
malformed packets are rejected during option validation.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-15 06:22
Updated : 2026-08-17 06:18
NVD link : CVE-2026-72351
Mitre link : CVE-2026-72351
CVE.ORG link : CVE-2026-72351
JSON object : View
Products Affected
No product.
CWE
No CWE.
