In the Linux kernel, the following vulnerability has been resolved:
ip_gre: test csum_start instead of transport header
GRE with TUNNEL_CSUM will apply local checksum offload on CHECKSUM_PARTIAL packets.
ipgre_xmit must validate csum_start after an optional skb_pull, else lco_csum may trigger an overflow. The original check was
if (csum && skb_checksum_start(skb) < skb->data) return -EINVAL;
This had false positives when skb_checksum_start is undefined: when ip_summed is not CHECKSUM_PARTIAL. A discussed refinement was straightforward
if (csum && skb->ip_summed == CHECKSUM_PARTIAL && skb_checksum_start(skb) < skb->data) return -EINVAL;
But was eventually revised more thoroughly: - restrict the check to the only branch where needed, in an uncommon GRE path that uses header_ops and calls skb_pull. - test skb_transport_header, which is set along with csum_start in skb_partial_csum_set in the normal header_ops datapath.
Turns out skbs can arrive in this branch without the transport header set, e.g., through BPF redirection.
Revise the check back to check csum_start directly, and only if CHECKSUM_PARTIAL. Do leave the check in the updated location. Check field regardless of whether TUNNEL_CSUM is configured.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernelUpgrade kernel-debuginfoUpgrade perfUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-develUpgrade kernel-tools-develUpgrade perf-debuginfoUpgrade kernel-toolsUpgrade kernel-livepatch-5.10.126-117.518Upgrade python-perfUpgrade kernel-livepatch-5.15.50-23.125Upgrade kernel-headersUpgrade python-perf-debuginfoUpgrade bpftoolUpgrade bpftool-debuginfoUpgrade kernel-tools-debuginfoUpgrade kernel-debuginfo-common-x86_64 | Mar 14, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernel-toolsUpgrade bpftoolUpgrade kernel-tools-libsUpgrade kernelUpgrade python3-perfUpgrade kernel-abi-stablelists | Oct 24, 2025 | Oct 23, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade linux-azure-5.4Upgrade linux-aws-5.4Upgrade linux-raspiUpgrade linuxUpgrade linux-ibm-5.4Upgrade linux-awsUpgrade linux-gcp-4.15Upgrade linux-hwe-5.15Upgrade linux-azure-4.15Upgrade linux-hweUpgrade linux-gcp-fipsUpgrade linux-gcp-5.4Upgrade linux-lowlatencyUpgrade linux-azureUpgrade linux-iotUpgrade linux-azure-fipsUpgrade linux-gkeopUpgrade linux-intel-iotgUpgrade linux-bluefieldUpgrade linux-fipsUpgrade linux-azure-fdeUpgrade linux-oracle-5.15Upgrade linux-azure-5.15Upgrade linux-riscv-5.15Upgrade linux-hwe-5.4Upgrade linux-oracleUpgrade linux-raspi-5.4Upgrade linux-nvidiaUpgrade linux-oracle-5.4Upgrade linux-gkeUpgrade linux-intel-iotg-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-aws-fipsUpgrade linux-aws-hweUpgrade linux-ibmUpgrade linux-realtimeUpgrade linux-aws-5.15Upgrade linux-gcpUpgrade linux-kvmUpgrade linux-gcp-5.15 | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub