In the Linux kernel, the following vulnerability has been resolved: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 raw_send_hdrinc() validates… (CVE-2026-64114)
In the Linux kernel, the following vulnerability has been resolved: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 raw_send_hdrinc() validates that the caller-supplied IPv4 header fits within the message length: iphlen = iph->ihl * 4; err = -EINVAL; if (iphlen > length) goto error_free; if (iphlen >= sizeof(*iph)) { /* fix up saddr, tot_len, id, csum, transport_header */ } It does not, however, reject ihl < 5. For such a packet the "if (iphlen >= sizeof(*iph))" branch is skipped, leaving the crafted iphdr untouched, but the packet is still handed to __ip_local_out() and onward. Downstream consumers that read iph->ihl assume a sane value: net/ipv4/ah4.c:ah_output() in particular subtracts sizeof(struct iphdr) from top_iph->ihl * 4 and passes the (signed-int-negative, then cast to size_t) result to memcpy(), producing an OOB access of length close to SIZE_MAX and a host kernel panic. An IPv4 header with ihl < 5 is malformed by definition (RFC 791: "Internet Header Length is the length of the internet header in 32 bit words ... Note that the minimum value for a correct header is 5."). The kernel should not be willing to inject such a packet into its own output path. Reject "iphlen < sizeof(*iph)" alongside the existing "iphlen > length" check. This matches the principle that locally constructed packets that re-enter the IP stack must pass the same basic sanity tests that a foreign packet would be subjected to. Once this lands, the "if (iphlen >= sizeof(*iph))" wrapper around the fixup branch becomes redundant; left in place to keep the patch minimal and backport-friendly. A follow-up can unwrap it. Note that commit 86f4c90a1c5c ("ipv4, ipv6: ensure raw socket message is big enough to hold an IP header") ensures the message buffer is large enough to hold an iphdr, but does not constrain the self-reported iph->ihl. Reachability: the malformed packet source is any caller with CAP_NET_RAW, including an unprivileged process in a user+net namespace on a kernel with CONFIG_USER_NS=y. The reproduced AH crash also requires a matching xfrm AH policy on the outgoing route; a container granted CAP_NET_ADMIN can install that state and policy in its netns. Loopback bypasses xfrm_output, so the trigger uses a real netdev. Reproduced on UML + KASAN: kernel-mode fault at addr 0x0 with memcpy_orig at the crash site. Same shape reproduces inside a rootless Docker container with --cap-add NET_ADMIN on a stock distro kernel.
AI Analysis
Technical Summary
The Linux kernel's raw_send_hdrinc() function did not reject IPv4 packets with an ihl (Internet Header Length) field less than 5, which is malformed by definition. This allowed crafted packets to bypass certain validation checks, leading to downstream consumers like net/ipv4/ah4.c:ah_output() performing out-of-bounds memory accesses. Specifically, ah_output() subtracts the size of a standard IPv4 header from the malformed ihl value, resulting in a large unsigned value passed to memcpy(), causing an out-of-bounds read and a kernel panic. The vulnerability was resolved by adding validation to reject packets with ihl < 5. The issue affects multiple Linux kernel versions prior to specified 5.15.0-xxx versions used in Ubuntu 20.04 LTS and related releases. The CVSS 3.1 score is 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating local attack vector with low complexity and significant impact on confidentiality, integrity, and availability. A patch is available from Ubuntu and other Linux vendors.
Potential Impact
Exploitation of this vulnerability can cause a host kernel panic due to out-of-bounds memory access, resulting in denial of service. The vulnerability also impacts confidentiality and integrity due to the potential for memory corruption. The CVSS score of 7.8 reflects high severity. The attack requires local privileges and low complexity but no user interaction. There are no known exploits in the wild at this time.
Mitigation Recommendations
A patch is available and should be applied promptly. Ubuntu has released fixed Linux kernel packages for affected versions, including 5.15.0-1112.119~20.04.1 and others. After applying the update, a system reboot is required. Due to an ABI change, third-party kernel modules must be recompiled and reinstalled. Follow vendor instructions for updating and recompiling modules. No additional mitigation is required beyond applying the official fix.
In the Linux kernel, the following vulnerability has been resolved: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 raw_send_hdrinc() validates… (CVE-2026-64114)
Description
In the Linux kernel, the following vulnerability has been resolved: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 raw_send_hdrinc() validates that the caller-supplied IPv4 header fits within the message length: iphlen = iph->ihl * 4; err = -EINVAL; if (iphlen > length) goto error_free; if (iphlen >= sizeof(*iph)) { /* fix up saddr, tot_len, id, csum, transport_header */ } It does not, however, reject ihl < 5. For such a packet the "if (iphlen >= sizeof(*iph))" branch is skipped, leaving the crafted iphdr untouched, but the packet is still handed to __ip_local_out() and onward. Downstream consumers that read iph->ihl assume a sane value: net/ipv4/ah4.c:ah_output() in particular subtracts sizeof(struct iphdr) from top_iph->ihl * 4 and passes the (signed-int-negative, then cast to size_t) result to memcpy(), producing an OOB access of length close to SIZE_MAX and a host kernel panic. An IPv4 header with ihl < 5 is malformed by definition (RFC 791: "Internet Header Length is the length of the internet header in 32 bit words ... Note that the minimum value for a correct header is 5."). The kernel should not be willing to inject such a packet into its own output path. Reject "iphlen < sizeof(*iph)" alongside the existing "iphlen > length" check. This matches the principle that locally constructed packets that re-enter the IP stack must pass the same basic sanity tests that a foreign packet would be subjected to. Once this lands, the "if (iphlen >= sizeof(*iph))" wrapper around the fixup branch becomes redundant; left in place to keep the patch minimal and backport-friendly. A follow-up can unwrap it. Note that commit 86f4c90a1c5c ("ipv4, ipv6: ensure raw socket message is big enough to hold an IP header") ensures the message buffer is large enough to hold an iphdr, but does not constrain the self-reported iph->ihl. Reachability: the malformed packet source is any caller with CAP_NET_RAW, including an unprivileged process in a user+net namespace on a kernel with CONFIG_USER_NS=y. The reproduced AH crash also requires a matching xfrm AH policy on the outgoing route; a container granted CAP_NET_ADMIN can install that state and policy in its netns. Loopback bypasses xfrm_output, so the trigger uses a real netdev. Reproduced on UML + KASAN: kernel-mode fault at addr 0x0 with memcpy_orig at the crash site. Same shape reproduces inside a rootless Docker container with --cap-add NET_ADMIN on a stock distro kernel.
CVSS v3.1
Score 7.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's raw_send_hdrinc() function did not reject IPv4 packets with an ihl (Internet Header Length) field less than 5, which is malformed by definition. This allowed crafted packets to bypass certain validation checks, leading to downstream consumers like net/ipv4/ah4.c:ah_output() performing out-of-bounds memory accesses. Specifically, ah_output() subtracts the size of a standard IPv4 header from the malformed ihl value, resulting in a large unsigned value passed to memcpy(), causing an out-of-bounds read and a kernel panic. The vulnerability was resolved by adding validation to reject packets with ihl < 5. The issue affects multiple Linux kernel versions prior to specified 5.15.0-xxx versions used in Ubuntu 20.04 LTS and related releases. The CVSS 3.1 score is 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating local attack vector with low complexity and significant impact on confidentiality, integrity, and availability. A patch is available from Ubuntu and other Linux vendors.
Potential Impact
Exploitation of this vulnerability can cause a host kernel panic due to out-of-bounds memory access, resulting in denial of service. The vulnerability also impacts confidentiality and integrity due to the potential for memory corruption. The CVSS score of 7.8 reflects high severity. The attack requires local privileges and low complexity but no user interaction. There are no known exploits in the wild at this time.
Mitigation Recommendations
A patch is available and should be applied promptly. Ubuntu has released fixed Linux kernel packages for affected versions, including 5.15.0-1112.119~20.04.1 and others. After applying the update, a system reboot is required. Due to an ABI change, third-party kernel modules must be recompiled and reinstalled. Follow vendor instructions for updating and recompiling modules. No additional mitigation is required beyond applying the official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mpq7-q79j-37gw
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64114"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a5d27a82a4a8d598912abe1
Added to database: 07/19/2026, 19:38:16 UTC
Last enriched: 08/22/2026, 14:28:47 UTC
Last updated: 09/02/2026, 22:52:13 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.