PT-2026-4673 · Linux+2 · Linux Kernel+2
Syzbot
·
Published
2026-01-01
·
Updated
2026-05-22
·
CVE-2026-23011
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains a flaw in the ipv4/ip gre module related to the
ipgre header() function. This issue can lead to kernel crashes when devices dynamically change their headroom or hard header length, potentially triggered by Multicast Listener Discovery (MLD) packets. The vulnerability was identified through syzbot testing, which found ways to crash the kernel by allocating an skb with insufficient reserve/headroom and then attaching an ipgre device. The fix involves making the ipgre header() function more robust, similar to a previous fix for the ip6 gre module.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu