← All Advisories

CVE-2026-97596

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97596

Key Details

CVECVE-2026-97596
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ipvs: reject invalid states in connection template sync records

IPVS sync receivers validate protocol states before creating or updating a

connection. For connection templates, however, they only log states outside

the template state range and still store the value in the connection.

A template can be returned by ordinary connection lookup. TCP and SCTP then

use the invalid state as an index into their transition tables.

Reject invalid template states in both sync protocol versions before

looking up or modifying a connection. The version 1 path handles both

IPv4 and IPv6 records. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97596
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97596