Junglewise Threat Intelligence

CVE-2025-38572: Linux Kernel transport header overflow in ipv6_gso_segment

CVE-2025-38572 · Severity: high · CVSS 7.8 · Published 2025-08-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's IPv6 networking component could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when the system processes specially crafted network packets with excessively long headers. This can lead to an internal memory overflow, compromising the stability and security of the operating system.

Technical details

A vulnerability exists in the ipv6_gso_segment() function within net/ipv6/ip6_offload.c of the Linux kernel. An attacker can craft a packet with excessively long IPv6 extension headers that causes an overflow of the 16-bit skb->transport_header field. This occurs during Generic Segmentation Offload (GSO) processing. The fix introduces a hardened helper function, skb_reset_transport_header_careful(), which performs bounds checking on the offset before updating the transport header. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.10.y, 6.11.y

Timeline

  • 2025-07-30: patched: Initial patch authored by Eric Dumazet
  • 2025-08-19: disclosed: CVE published to NVD

References

Related threats