PT-2025-53934 · Linux+2 · Linux Kernel+2

CVE-2022-50816

·

Published

2025-12-30

·

Updated

2026-02-12

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.0.0-rc7-syzkaller-18095-gbbed346d5a96
Description The Linux kernel contained a flaw in the IPv6 tunnel implementation. Specifically, the code did not properly sanitize the Maximum Transmission Unit (MTU) value, potentially allowing a layer to set the device MTU to an underflowed value. This could lead to a kernel bug, as demonstrated by a syzbot report and a resulting panic when handling skbuffs (socket buffer structures). The issue was identified in the ip6 gre tunnel (dev:ip6gretap0) and related functions like ip6 tnl link config route(), ip6 tnl link config(), and ipip6 tunnel bind dev().
Recommendations Update to version 6.0.0-rc7-syzkaller-18095-gbbed346d5a96 or a later version to address this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-50816
OESA-2026-1276
RHSA-2023:2458
RHSA-2023:7077
SUSE-SU-2026:0473-1

Affected Products

Centos
Linux Kernel
Red Hat