Junglewise Threat Intelligence

CVE-2025-39770: Linux Kernel network throughput collapse in IPv6 GSO extension handling

CVE-2025-39770 · Severity: medium · CVSS 5.5 · Published 2025-09-11

Technologies: Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's networking stack can cause a significant drop in network performance or a complete loss of connectivity. This occurs when the system processes specific types of IPv6 traffic (such as encrypted tunnels) on hardware that does not support certain advanced features. An exploit could lead to a denial-of-service condition, impacting the availability of network-dependent services and operations.

Technical details

A logic error exists in the Generic Segmentation Offload (GSO) stack of the Linux kernel. When processing IPv6 packets containing extension headers (e.g., GREoIPv6), the kernel incorrectly requests checksum offload even if the egress device only supports NETIF_F_IPV6_CSUM. This violates the hardware contract, which only supports plain TCP/UDP over IPv6 without extensions. The resulting mismatch triggers 'skb_warn_bad_offload' warnings and causes network throughput to collapse. The fix involves masking NETIF_F_IPV6_CSUM, NETIF_F_TSO6, and NETIF_F_GSO_UDP_L4 in 'gso_features_check' when extension headers are detected, forcing the checksum to be computed in software.

Affected products

  • Linux Linux Kernel versions prior to 6.14-rc1
  • Siemens SIMATIC CN 4100 versions prior to V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5 and later

Timeline

  • 2025-08-14: disclosed: Initial patch submission
  • 2025-08-28: patched: Patch committed to stable tree
  • 2025-09-11: advisory: CVE published

References

Related threats