CVE-2022-49691: erspan: do not assume transport header is always set

Published Feb 26, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

erspan: do not assume transport header is always set

Rewrite tests in ip6erspantunnelxmit() and erspanfbxmit() to not assume transport header is set.

syzbot reported:

WARNING: CPU: 0 PID: 1350 at include/linux/skbuff.h:2911 skbtransportheader include/linux/skbuff.h:2911 [inline] WARNING: CPU: 0 PID: 1350 at include/linux/skbuff.h:2911 ip6erspantunnelxmit+0x15af/0x2eb0 net/ipv6/ip6gre.c:963 Modules linked in: CPU: 0 PID: 1350 Comm: aoetx0 Not tainted 5.19.0-rc2-syzkaller-00160-g274295c6e53f #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014 RIP: 0010:skbtransportheader include/linux/skbuff.h:2911 [inline] RIP: 0010:ip6erspantunnelxmit+0x15af/0x2eb0 net/ipv6/ip6gre.c:963 Code: 0f 47 f0 40 88 b5 7f fe ff ff e8 8c 16 4b f9 89 de bf ff ff ff ff e8 a0 12 4b f9 66 83 fb ff 0f 85 1d f1 ff ff e8 71 16 4b f9 <0f> 0b e9 43 f0 ff ff e8 65 16 4b f9 48 8d 85 30 ff ff ff ba 60 00 RSP: 0018:ffffc90005daf910 EFLAGS: 00010293 RAX: 0000000000000000 RBX: 000000000000ffff RCX: 0000000000000000 RDX: ffff88801f032100 RSI: ffffffff882e8d3f RDI: 0000000000000003 RBP: ffffc90005dafab8 R08: 0000000000000003 R09: 000000000000ffff R10: 000000000000ffff R11: 0000000000000000 R12: ffff888024f21d40 R13: 000000000000a288 R14: 00000000000000b0 R15: ffff888025a2e000 FS: 0000000000000000(0000) GS:ffff88802c800000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000001b2e425000 CR3: 000000006d099000 CR4: 0000000000152ef0 Call Trace: <TASK> netdevstartxmit include/linux/netdevice.h:4805 [inline] netdevstartxmit include/linux/netdevice.h:4819 [inline] xmitone net/core/dev.c:3588 [inline] devhardstartxmit+0x188/0x880 net/core/dev.c:3604 schdirectxmit+0x19f/0xbe0 net/sched/schgeneric.c:342 devxmitskb net/core/dev.c:3815 [inline] devqueuexmit+0x14a1/0x3900 net/core/dev.c:4219 devqueuexmit include/linux/netdevice.h:2994 [inline] tx+0x6a/0xc0 drivers/block/aoe/aoenet.c:63 kthread+0x1e7/0x3b0 drivers/block/aoe/aoecmd.c:1229 kthread+0x2e9/0x3a0 kernel/kthread.c:376 retfromfork+0x1f/0x30 arch/x86/entry/entry64.S:302 </TASK>

Affected Software

9 affected components
Linux Linux kernel
Linux Linux kernel>=4.18<4.19.250
Linux Linux kernel>=4.20<5.4.202
Linux Linux kernel>=5.5<5.10.127
Linux Linux kernel>=5.11<5.15.51
Linux Linux kernel>=5.16<5.18.8
Linux Linux kernel=5.19-rc1
Linux Linux kernel=5.19-rc2
Linux Linux kernel=5.19-rc3

Event History

Feb 26, 2025
CVE Published
via MITRE·02:24 AM
Data Sourced
via MITRE·02:24 AM
Description
Data Sourced
via NVD·07:01 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2022-49691?

CVE-2022-49691 has been classified with a low severity level as it involves an issue in the Linux kernel related to assumptions made about transport headers.

2

How do I fix CVE-2022-49691?

To fix CVE-2022-49691, update your Linux kernel to the latest version where this vulnerability has been patched.

3

What systems are affected by CVE-2022-49691?

CVE-2022-49691 affects various versions of the Linux Kernel that utilize erspan functionalities.

4

What type of vulnerability is CVE-2022-49691?

CVE-2022-49691 is a coding assumption vulnerability that arises from not verifying the presence of transport headers in the Linux kernel.

5

Who reported CVE-2022-49691?

The CVE-2022-49691 vulnerability was reported by syzbot, an automated testing tool for the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203