Junglewise Threat Intelligence

CVE-2025-71098: Linux Kernel denial of service in ip6gre_header

CVE-2025-71098 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Linux Kernel, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP. Vendors: Linux, Siemens.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when specific network tunneling features (GRE over IPv6) interact with network bonding drivers, leading to a kernel panic. This results in a complete loss of availability for the affected system, potentially disrupting operations or services.

Technical details

A vulnerability exists in the ip6gre_header() function within net/ipv6/ip6_gre.c of the Linux kernel. The root cause is a failure to ensure sufficient headroom in the socket buffer (skb) before calling skb_push(), particularly when team or bonding drivers dynamically modify dev->needed_headroom or dev->hard_header_len. An attacker with local access can trigger a kernel BUG (skb_under_panic) by attaching an ip6gre device to a packet with insufficient reserved space, leading to a denial of service. The fix involves making ip6gre_header() robust by checking headroom and using pskb_expand_head() if necessary. Patches have been released for various stable kernel branches.

Affected products

  • Linux Linux Kernel c12b395a46646bab69089ce7016ac78177f6001f to 17e7386234f740f3e7d5e58a47b5847ea34c3bc2
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6

Timeline

  • 2025-12-11: other: Patch authored by Eric Dumazet
  • 2026-01-11: patched: Committed to stable tree by Greg Kroah-Hartman
  • 2026-01-13: advisory: CVE published

References

Related threats