All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
Date: Wed,  5 Aug 2026 10:09:26 +0200	[thread overview]
Message-ID: <2026080524-CVE-2026-64577-0dfc@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

gtp: check skb_pull_data() return in gtp1u_send_echo_resp()

gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its
caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +
gtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For
a 16-19 byte echo request the pull fails and returns NULL without
advancing skb->data; execution continues, and the following skb_push()
plus the IP header pushed by iptunnel_xmit() move skb->data below
skb->head, tripping skb_under_panic().

Fix it by dropping the packet when skb_pull_data() fails.

  skbuff: skb_under_panic: ...
  kernel BUG at net/core/skbuff.c:214!
  Call Trace:
   skb_push (net/core/skbuff.c:2648)
   iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)
   gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)
   udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)
   ...
  Kernel panic - not syncing: Fatal exception in interrupt

The Linux kernel CVE team has assigned CVE-2026-64577 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.18 with commit 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 and fixed in 6.6.148 with commit b3c733eaae7f362601c28ac1533d47a961cd3e1c
	Issue introduced in 5.18 with commit 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 and fixed in 6.12.101 with commit 4fc7923871d176ce0e5fecf4a9b7bb915af790ed
	Issue introduced in 5.18 with commit 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 and fixed in 6.18.42 with commit 961e9b1e33445f8e42859ecc020c9f60d8b69a8b
	Issue introduced in 5.18 with commit 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 and fixed in 7.1.6 with commit cf45d748e437b8dd2dd987f27ee79c8c86f95c88
	Issue introduced in 5.18 with commit 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 and fixed in 7.2-rc5 with commit cd170f051dba9ac146fabcd1b91726487c0cb9fa

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64577
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/net/gtp.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/b3c733eaae7f362601c28ac1533d47a961cd3e1c
	https://git.kernel.org/stable/c/4fc7923871d176ce0e5fecf4a9b7bb915af790ed
	https://git.kernel.org/stable/c/961e9b1e33445f8e42859ecc020c9f60d8b69a8b
	https://git.kernel.org/stable/c/cf45d748e437b8dd2dd987f27ee79c8c86f95c88
	https://git.kernel.org/stable/c/cd170f051dba9ac146fabcd1b91726487c0cb9fa

                 reply	other threads:[~2026-08-05  8:09 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026080524-CVE-2026-64577-0dfc@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.