CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026080524-CVE-2026-64577-0dfc@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr + gtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For a 16-19 byte echo request the pull fails and returns NULL without advancing skb->data; execution continues, and the following skb_push() plus the IP header pushed by iptunnel_xmit() move skb->data below skb->head, tripping skb_under_panic(). Fix it by dropping the packet when skb_pull_data() fails. skbuff: skb_under_panic: ... kernel BUG at net/core/skbuff.c:214! Call Trace: skb_push (net/core/skbuff.c:2648) iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82) gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920) udp_queue_rcv_one_skb (net/ipv4/udp.c:2388) ... Kernel panic - not syncing: Fatal exception in interrupt The Linux kernel CVE team has assigned CVE-2026-64577 to this issue. Affected and fixed versions =========================== Issue introduced in 5.18 with commit 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 and fixed in 6.6.148 with commit b3c733eaae7f362601c28ac1533d47a961cd3e1c Issue introduced in 5.18 with commit 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 and fixed in 6.12.101 with commit 4fc7923871d176ce0e5fecf4a9b7bb915af790ed Issue introduced in 5.18 with commit 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 and fixed in 6.18.42 with commit 961e9b1e33445f8e42859ecc020c9f60d8b69a8b Issue introduced in 5.18 with commit 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 and fixed in 7.1.6 with commit cf45d748e437b8dd2dd987f27ee79c8c86f95c88 Issue introduced in 5.18 with commit 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 and fixed in 7.2-rc5 with commit cd170f051dba9ac146fabcd1b91726487c0cb9fa Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64577 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/gtp.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/b3c733eaae7f362601c28ac1533d47a961cd3e1c https://git.kernel.org/stable/c/4fc7923871d176ce0e5fecf4a9b7bb915af790ed https://git.kernel.org/stable/c/961e9b1e33445f8e42859ecc020c9f60d8b69a8b https://git.kernel.org/stable/c/cf45d748e437b8dd2dd987f27ee79c8c86f95c88 https://git.kernel.org/stable/c/cd170f051dba9ac146fabcd1b91726487c0cb9fa