CVE-2026-72351
In the Linux kernel, the following vulnerability has been resolved:
gue: validate REMCSUM private option length
GUE private flags can indicate that remote checksum offload metadata is
present. The private flags field itself is accounted for by
guehdrflagslen(), but guehdrprivflags_len() currently returns 0 even
when GUEPFLAGREMCSUM is set.
This lets a packet with only the private flags field pass
validategueflags(), after which gueremcsum() and guegro_remcsum()
read the missing REMCSUM start/offset fields from the following bytes.
Account for GUEPLENREMCSUM when GUEPFLAGREMCSUM is present so that
malformed packets are rejected during option validation.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/158b9995d3c87f3b93f5c22df54a12e12a3438b3, https://git.kernel.org/stable/c/2a99224c120823987e4d829726f4ecb33e03fc1e, https://git.kernel.org/stable/c/2c4de9988e9ddc760b750d6b6e701c35ff60ad14, https://git.kernel.org/stable/c/4a4a1d41c6e901e773bcf795f562a47fa71f692a, https://git.kernel.org/stable/c/61e78679c7c9ca685bff58e4b6348304dc60aafd, https://git.kernel.org/stable/c/7c6876ec1b227261b51803f784c7be1b2242a1a0, https://git.kernel.org/stable/c/d335dcc6f521571d57117b8deeebc940836e5450, https://git.kernel.org/stable/c/f618cbe9b24cd0202004d2db781d5f80ab77037f, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72351.json, https://nvd.nist.gov/vuln/detail/CVE-2026-72351, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git