CVE-2026-72442
In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: fix and simplify IP6IP6 tunnel handling
Fix nfflowip6tunnelproto() to use pskbmaypull() instead of
skbheaderpointer() to ensure the outer IPv6 header is in the skb
headroom, which is required for subsequent packet processing. Move
ctx->offset update inside the IPPROTO_IPV6 conditional block since it
should only be adjusted when an IP6IP6 tunnel is actually detected.
Simplify the rx path by removing ipv6skipexthdr() and checking
ip6h->nexthdr directly, as the flowtable fast path only handles simple
IP6IP6 encapsulation without extension headers.
Drop the tunnel encapsulation limit destination option support from the
tx path to match, since the rx path no longer handles extension headers.
Remove the encaplimit parameter from nfflowoffloadipv6_forward(),
nfflowtunnelip6ip6push() and nfflowtunnelv6push(), along with
the ipv6teltxoption struct and related headroom/MTU adjustments.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/7f8d816a9aa2729d270418f00c9ef5e85bfc1b31, https://git.kernel.org/stable/c/f4c2d8668d85ed125985da663c824a9c25498257, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72442.json, https://nvd.nist.gov/vuln/detail/CVE-2026-72442, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git