Junglewise Threat Intelligence

CVE-2025-68363: Linux Kernel BPF uninitialized transport header in bpf_skb_check_mtu

CVE-2025-68363 · Severity: info · CVSS 0 · Published 2025-12-24

Technologies: Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP. Vendors: Linux, Siemens.

Executive brief

A vulnerability was identified in the Linux kernel's networking subsystem, specifically within the BPF (Berkeley Packet Filter) component used for high-performance packet processing. Under certain conditions, the system could attempt to access network packet data that hasn't been properly initialized, potentially leading to system instability or crashes. This issue primarily affects specialized networking configurations and testing environments, and it has been resolved in recent kernel updates.

Technical details

A vulnerability in 'net/core/filter.c' within the Linux kernel's BPF implementation occurred because the 'bpf_skb_check_mtu' helper did not verify if 'skb->transport_header' was initialized when the 'BPF_MTU_CHK_SEGS' flag was used. This lack of validation could trigger a 'WARN_ON_ONCE' in 'skb_gso_validate_network_len' when 'CONFIG_DEBUG_NET' is enabled, particularly during 'bpf_prog_test_run'. The fix introduces a check using 'skb_transport_header_was_set()' before accessing the header to ensure the socket buffer is in a valid state for MTU validation. The issue affects kernels from version 5.12 up to various stable branches (6.1, 6.6, 6.11, 6.12).

Affected products

  • Linux Linux 5.12 to 6.12.y
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later

Timeline

  • 2025-11-12: disclosed: Initial patch submitted by Martin KaFai Lau
  • 2025-12-18: patched: Commits merged into stable branches
  • 2025-12-24: advisory: CVE published

References

Related threats