{"id":"CVE-2026-97417","published":"2026-09-24T17:17:19.457","lastModified":"2026-09-25T13:17:25.243","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()\n\nThe timestamp-only fast path dereferences the option stream as\n*(__be32 *)ptr, which assumes 4-byte alignment that the TCP option\nstream does not guarantee. Use get_unaligned_be32() instead, which\nreads the value safely and already returns host byte order, so the\nhtonl() on the comparison constant can be dropped.\n\nThis matches the existing get_unaligned_be32() use later in the same\nfunction.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/4abc1af7ac209c066f4e5dd75cdd56876e5829a9","tags":[]},{"url":"https://git.kernel.org/stable/c/7ecfa46a536578a7ed335ddf31a854127268c27c","tags":[]},{"url":"https://git.kernel.org/stable/c/d3bf9eae486490832bd08fd62ab0ac601f346bd4","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}