Answer in brief
CVE-2026-97596 records a Unknown severity vulnerability in ipvs: reject invalid states in connection template sync records. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=275411430f892407b885be1de2548b2e632892c3 <fc10dc4511e6e2e2b4098ee115c8e5639471f23d || >=275411430f892407b885be1de2548b2e632892c3 <50c3f06222eafe9cca7ca51a0ef83311d7cab353 || >=275411430f892407b885be1de2548b2e632892c3 <0c61f7d8e18a978aec2a16d9acd5f682f1c72476 || >=275411430f892407b885be1de2548b2e632892c3 <74cb39735b6cd0aff4b5584158f09376fd97aadf | fc10dc4511e6e2e2b4098ee115c8e5639471f23d, 50c3f06222eafe9cca7ca51a0ef83311d7cab353, 0c61f7d8e18a978aec2a16d9acd5f682f1c72476, 74cb39735b6cd0aff4b5584158f09376fd97aadf |
| Linux/Linuxgeneric | 4.19 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: ipvs: reject invalid states in connection template sync records IPVS sync receivers validate protocol states before creating or updating a connection. For connection templates, however, they only log states outside the template state range and still store the value in the connection. A template can be returned by ordinary connection lookup. TCP and SCTP then use the invalid state as an index into their transition tables. Reject invalid template states in both sync protocol versions before looking up or modifying a connection. The version 1 path handles both IPv4 and IPv6 records.
Quoted source text, attributed separately from HOL analysis.