Executive brief
A vulnerability in the Linux kernel's IPv6 networking component could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when the system processes specially crafted network packets with excessively long headers. This can lead to an internal memory overflow, compromising the stability and security of the operating system.
Technical details
A vulnerability exists in the ipv6_gso_segment() function within net/ipv6/ip6_offload.c of the Linux kernel. An attacker can craft a packet with excessively long IPv6 extension headers that causes an overflow of the 16-bit skb->transport_header field. This occurs during Generic Segmentation Offload (GSO) processing. The fix introduces a hardened helper function, skb_reset_transport_header_careful(), which performs bounds checking on the offset before updating the transport header. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux Kernel 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.10.y, 6.11.y
Timeline
- 2025-07-30: patched: Initial patch authored by Eric Dumazet
- 2025-08-19: disclosed: CVE published to NVD
References
- https://git.kernel.org/stable/c/09ff062b89d8e48165247d677d1ca23d6d607e9b
- https://git.kernel.org/stable/c/3f638e0b28bde7c3354a0df938ab3a96739455d1
- https://git.kernel.org/stable/c/5489e7fc6f8be3062f8cb7e49406de4bfd94db67
- https://git.kernel.org/stable/c/573b8250fc2554761db3bc2bbdbab23789d52d4e
- https://git.kernel.org/stable/c/5dc60b2a00ed7629214ac0c48e43f40af2078703
- https://git.kernel.org/stable/c/d45cf1e7d7180256e17c9ce88e32e8061a7887fe
- https://git.kernel.org/stable/c/de322cdf600fc9433845a9e944d1ca6b31cfb67e