PT-2025-4310 · Linux+5 · Linux Kernel+5

Eric Dumazet

+1

·

Published

2025-01-01

·

Updated

2026-05-26

·

CVE-2025-21629

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.74
Description The issue concerns the Linux kernel's handling of IPv6 packets with extension headers. Specifically, it affects devices that advertise NETIF F IPV6 CSUM, which is a feature for checksumming plain TCP or UDP packets over IPv6. The problem arises when BIG TCP packets are used, introducing an IPV6 TLV JUMBO IPv6 extension header to communicate packet length. This header is not transmitted by physical devices but is present for PF PACKET taps like tcpdump. The change that caused the issue disabled hardware offload of IPv6 packets with extension headers on devices that support NETIF F IPV6 CSUM. The ipv6 has hopopt jumbo() function tests for the presence of this header and ensures it is the only extension header before a terminal (L4) header. The issue has been resolved by reenabling NETIF F IPV6 CSUM offload for BIG TCP packets.
Recommendations For Linux kernel versions prior to 6.6.74, update to version 6.6.74 or later to resolve the issue. As a temporary workaround, consider disabling the skb warn bad offload() function until a patch is available. Restrict access to the vulnerable NETIF F IPV6 CSUM feature to minimize the risk of exploitation. Avoid using the IPV6 TLV JUMBO extension header in BIG TCP packets until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

AZL-68552
BDU:2025-04724
CVE-2025-21629
DLA-4076-1
MGASA-2025-0030
MGASA-2025-0032
OESA-2025-1320
OESA-2025-1321
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_02000-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu