In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as struct inet6_skb_parm. icmp_send() passes IPCB(skb2) to __ip_options_echo(), which interprets that cb[] region as struct inet_skb_parm (IPv4). The layouts differ: inet6_skb_parm.nhoff at offset 14 overlaps inet_skb_parm.opt.rr, producing a non-zero rr value. __ip_options_echo() then reads optlen from attacker-controlled packet data at sptr[rr+1] and copies that many bytes into dopt->__data, a fixed 40-byte stack buffer (IP_OPTIONS_DATA_FIXED_SIZE). To fix this we clear skb2->cb[], as suggested by Oskar Kjos. Also add minimal IPv4 header validation (version == 4, ihl >= 5).
Update Linux/Linux to ea9f65b27c8404e164848ebff1443310fd187629 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanip6_tunnel: clear skb2->cb[] in ip4ip6_err() affects Linux/Linux (generic), Linux/Linux (generic). Severity is critical. In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as struct inet6_skb_parm. icmp_send() passes IPCB(skb2) to __ip_options_echo(), which interprets that cb[] region as struct inet_skb_parm (IPv4). The layouts differ: inet6_skb_parm.nhoff at offset 14 overlaps inet_skb_parm.opt.rr, producing a non-zero rr value. __ip_options_echo() then reads optlen from attacker-controlled packet data at sptr[rr+1] and copies that many bytes into dopt->__data, a fixed 40-byte stack buffer (IP_OPTIONS_DATA_FIXED_SIZE). To fix this we clear skb2->cb[], as suggested by Oskar Kjos. Also add minimal IPv4 header validation (version == 4, ihl >= 5).
AI coding agents often install or upgrade packages automatically in generic. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range |
|---|
In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as struct inet6_skb_parm. icmp_send() passes IPCB(skb2) to __ip_options_echo(), which interprets that cb[] region as struct inet_skb_parm (IPv4). The layouts differ: inet6_skb_parm.nhoff at offset 14 overlaps inet_skb_parm.opt.rr, producing a non-zero rr value. __ip_options_echo() then reads optlen from attacker-controlled packet data at sptr[rr+1] and copies that many bytes into dopt->__data, a fixed 40-byte stack buffer (IP_OPTIONS_DATA_FIXED_SIZE). To fix this we clear skb2->cb[], as suggested by Oskar Kjos. Also add minimal IPv4 header validation (version == 4, ihl >= 5).
Update Linux/Linux to ea9f65b27c8404e164848ebff1443310fd187629 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanip6_tunnel: clear skb2->cb[] in ip4ip6_err() affects Linux/Linux (generic), Linux/Linux (generic). Severity is critical. In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as struct inet6_skb_parm. icmp_send() passes IPCB(skb2) to __ip_options_echo(), which interprets that cb[] region as struct inet_skb_parm (IPv4). The layouts differ: inet6_skb_parm.nhoff at offset 14 overlaps inet_skb_parm.opt.rr, producing a non-zero rr value. __ip_options_echo() then reads optlen from attacker-controlled packet data at sptr[rr+1] and copies that many bytes into dopt->__data, a fixed 40-byte stack buffer (IP_OPTIONS_DATA_FIXED_SIZE). To fix this we clear skb2->cb[], as suggested by Oskar Kjos. Also add minimal IPv4 header validation (version == 4, ihl >= 5).
AI coding agents often install or upgrade packages automatically in generic. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range |
|---|
| Fixed version |
|---|
| Linux/Linuxgeneric | >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <ea9f65b27c8404e164848ebff1443310fd187629 || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <d6621f60192fe10c047a4487be42a6f4c150707f || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <2cc6e3b0fe0f0242d1f530a93a4924f48ab85ba5 || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <a0c4ce9900a108eaf55d0f3b399cb55999647d39 || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <1063515ce15ff31065c4e7f8265f4c2fd3c54876 || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <590f622669b97eaf7b57a1de7b0a6e68c5d8b2c3 || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <4a622658f384b03560834cbe8ffcfe69a278f7c8 || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <2edfa31769a4add828a7e604b21cb82aaaa05925 | ea9f65b27c8404e164848ebff1443310fd187629, d6621f60192fe10c047a4487be42a6f4c150707f, 2cc6e3b0fe0f0242d1f530a93a4924f48ab85ba5, a0c4ce9900a108eaf55d0f3b399cb55999647d39, 1063515ce15ff31065c4e7f8265f4c2fd3c54876, 590f622669b97eaf7b57a1de7b0a6e68c5d8b2c3, 4a622658f384b03560834cbe8ffcfe69a278f7c8, 2edfa31769a4add828a7e604b21cb82aaaa05925 |
|---|---|---|
| Linux/Linuxgeneric | 2.6.22 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Fixed version |
|---|
| Linux/Linuxgeneric | >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <ea9f65b27c8404e164848ebff1443310fd187629 || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <d6621f60192fe10c047a4487be42a6f4c150707f || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <2cc6e3b0fe0f0242d1f530a93a4924f48ab85ba5 || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <a0c4ce9900a108eaf55d0f3b399cb55999647d39 || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <1063515ce15ff31065c4e7f8265f4c2fd3c54876 || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <590f622669b97eaf7b57a1de7b0a6e68c5d8b2c3 || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <4a622658f384b03560834cbe8ffcfe69a278f7c8 || >=c4d3efafcc933fd2ffd169d7dc4f980393a13796 <2edfa31769a4add828a7e604b21cb82aaaa05925 | ea9f65b27c8404e164848ebff1443310fd187629, d6621f60192fe10c047a4487be42a6f4c150707f, 2cc6e3b0fe0f0242d1f530a93a4924f48ab85ba5, a0c4ce9900a108eaf55d0f3b399cb55999647d39, 1063515ce15ff31065c4e7f8265f4c2fd3c54876, 590f622669b97eaf7b57a1de7b0a6e68c5d8b2c3, 4a622658f384b03560834cbe8ffcfe69a278f7c8, 2edfa31769a4add828a7e604b21cb82aaaa05925 |
|---|---|---|
| Linux/Linuxgeneric | 2.6.22 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard