PT-2025-53934 · Linux+2 · Linux Kernel+2
CVE-2022-50816
·
Published
2025-12-30
·
Updated
2026-02-12
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.0.0-rc7-syzkaller-18095-gbbed346d5a96
Description
The Linux kernel contained a flaw in the IPv6 tunnel implementation. Specifically, the code did not properly sanitize the Maximum Transmission Unit (MTU) value, potentially allowing a layer to set the device MTU to an underflowed value. This could lead to a kernel bug, as demonstrated by a syzbot report and a resulting panic when handling skbuffs (socket buffer structures). The issue was identified in the ip6 gre tunnel (dev:ip6gretap0) and related functions like ip6 tnl link config route(), ip6 tnl link config(), and ipip6 tunnel bind dev().
Recommendations
Update to version 6.0.0-rc7-syzkaller-18095-gbbed346d5a96 or a later version to address this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Linux Kernel
Red Hat