UNKNOWN NVD
CVE-2026-98078
In the Linux kernel, the following vulnerability has been resolved: ipvs: fix reversed sequence option serialization hton_seq() expects the host-order source
In the Linux kernel, the following vulnerability has been resolved:
ipvs: fix reversed sequence option serialization
hton_seq() expects the host-order source first and the unaligned
network-order destination second. The version 1 sync sender passes these
arguments in reverse for both sequence blocks. This leaves 24 bytes of the
kmalloc-backed message unwritten. It may disclose stale heap data and
replace the live connection sequence state with values read from the
buffer.
Pass the connection sequence state as the source and the message payload as
the destination for both blocks.
References
- https://git.kernel.org/stable/c/524599714558da83747c04952d378155c69f5b6b
- https://git.kernel.org/stable/c/b04578b74f2d3755548fe9e829e3b2a6c6f966a1
- https://git.kernel.org/stable/c/de6cc6ec7932bc530f2bb92005dac9123d50659c
- https://git.kernel.org/stable/c/e1c9f9446d3eaae323f1689f9e5de3b1ad6e47ec
This unknown severity vulnerability was published on 2026-09-25 via NVD.
vulnfeed aggregates 11443 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.