CVE-2025-71098: ip6_gre: make ip6gre_header() robust

Published Jan 13, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ip6gre: make ip6greheader() robust

Over the years, syzbot found many ways to crash the kernel in ip6greheader() [1].

This involves team or bonding drivers ability to dynamically change their dev->neededheadroom and/or dev->hardheaderlen

In this particular crash mldnewpack() allocated an skb with a too small reserve/headroom, and by the time mldsendpack() was called, syzbot managed to attach an ip6gre device.

[1] skbuff: skbunderpanic: text:ffffffff8a1d69a8 len:136 put:40 head:ffff888059bc7000 data:ffff888059bc6fe8 tail:0x70 end:0x6c0 dev:team0 ------------[ cut here ]------------ kernel BUG at net/core/skbuff.c:213 ! <TASK> skbunderpanic net/core/skbuff.c:223 [inline] skbpush+0xc3/0xe0 net/core/skbuff.c:2641 ip6greheader+0xc8/0x790 net/ipv6/ip6gre.c:1371 devhardheader include/linux/netdevice.h:3436 [inline] neighconnectedoutput+0x286/0x460 net/core/neighbour.c:1618 neighoutput include/net/neighbour.h:556 [inline] ip6finishoutput2+0xfb3/0x1480 net/ipv6/ip6output.c:136 ip6finishoutput net/ipv6/ip6output.c:-1 [inline] ip6finishoutput+0x234/0x7d0 net/ipv6/ip6output.c:220 NFHOOKCOND include/linux/netfilter.h:307 [inline] ip6output+0x340/0x550 net/ipv6/ip6output.c:247 NFHOOK+0x9e/0x380 include/linux/netfilter.h:318 mldsendpack+0x8d4/0xe60 net/ipv6/mcast.c:1855 mldsendcr net/ipv6/mcast.c:2154 [inline] mldifcwork+0x83e/0xd60 net/ipv6/mcast.c:2693

Affected Software

17 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.119.3-3
Linux Linux kernel>=3.7.1<5.10.248
Linux Linux kernel>=5.11<5.15.198
Linux Linux kernel>=5.16<6.1.160
Linux Linux kernel>=6.2<6.6.120
Linux Linux kernel>=6.7<6.12.64
Linux Linux kernel>=6.13<6.18.4
Linux Linux kernel=3.7
Linux Linux kernel=6.19-rc1
Linux Linux kernel=6.19-rc2
Linux Linux kernel=6.19-rc3
Linux Linux kernel=6.19-rc4
Linux Linux kernel=6.19-rc5
Linux Linux kernel=6.19-rc6
Linux Linux kernel=6.19-rc7
Linux Linux kernel=6.19-rc8

Event History

Jan 13, 2026
CVE Published
via MITRE·03:34 PM
Data Sourced
via MITRE·03:34 PM
Description
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 15, 2026
Data Sourced
via Microsoft·09:06 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·09:06 AM
Affected Software
Updated
via Microsoft·09:06 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2025-71098?

CVE-2025-71098 is classified as a medium-severity vulnerability in the Linux kernel.

2

How do I fix CVE-2025-71098?

Fixing CVE-2025-71098 involves updating the Linux kernel to the latest version that contains the security patch.

3

What impact does CVE-2025-71098 have on Linux systems?

CVE-2025-71098 can lead to kernel crashes, potentially affecting system stability and availability.

4

Which versions of the Linux kernel are affected by CVE-2025-71098?

CVE-2025-71098 affects various versions of the Linux kernel that utilize the ip6gre_header functionality.

5

Who disclosed CVE-2025-71098?

CVE-2025-71098 was disclosed through the syzbot initiative, which tests for vulnerabilities in the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203