Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when specific network tunneling features (GRE over IPv6) interact with network bonding drivers, leading to a kernel panic. This results in a complete loss of availability for the affected system, potentially disrupting operations or services.
Technical details
A vulnerability exists in the ip6gre_header() function within net/ipv6/ip6_gre.c of the Linux kernel. The root cause is a failure to ensure sufficient headroom in the socket buffer (skb) before calling skb_push(), particularly when team or bonding drivers dynamically modify dev->needed_headroom or dev->hard_header_len. An attacker with local access can trigger a kernel BUG (skb_under_panic) by attaching an ip6gre device to a packet with insufficient reserved space, leading to a denial of service. The fix involves making ip6gre_header() robust by checking headroom and using pskb_expand_head() if necessary. Patches have been released for various stable kernel branches.
Affected products
- Linux Linux Kernel c12b395a46646bab69089ce7016ac78177f6001f to 17e7386234f740f3e7d5e58a47b5847ea34c3bc2
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
Timeline
- 2025-12-11: other: Patch authored by Eric Dumazet
- 2026-01-11: patched: Committed to stable tree by Greg Kroah-Hartman
- 2026-01-13: advisory: CVE published
References
- https://git.kernel.org/stable/c/1717357007db150c2d703f13f5695460e960f26c
- https://git.kernel.org/stable/c/17e7386234f740f3e7d5e58a47b5847ea34c3bc2
- https://git.kernel.org/stable/c/41a1a3140aff295dee8063906f70a514548105e8
- https://git.kernel.org/stable/c/5fe210533e3459197eabfdbf97327dacbdc04d60
- https://git.kernel.org/stable/c/91a2b25be07ce1a7549ceebbe82017551d2eec92
- https://git.kernel.org/stable/c/adee129db814474f2f81207bd182bf343832a52e
- https://git.kernel.org/stable/c/db5b4e39c4e63700c68a7e65fc4e1f1375273476