← Back to search

CVE-2026-64577

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-08

AI risk analysis

Summary
This vulnerability in the Linux kernel's GTP (Generic Tunneling Protocol) implementation allows a malicious packet with specific payload to cause a kernel panic by triggering an invalid memory access.
Exploitability
Exploitation requires crafting a specially crafted GTP echo request packet that fails skb_pull_data(), making it moderately difficult but feasible for attackers with network control over the interface.
Blast radius
If exploited, this could lead to a denial of service (DoS) condition on affected systems, potentially causing kernel crashes and system instability.
Prioritized remediation
Update the Linux kernel to the patched version as soon as possible to mitigate this vulnerability.
doskernelgtp

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr + gtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For a 16-19 byte echo request the pull fails and returns NULL without advancing skb->data; execution continues, and the following skb_push() plus the IP header pushed by iptunnel_xmit() move skb->data below skb->head, tripping skb_under_panic(). Fix it by dropping the packet when skb_pull_data() fails. skbuff: skb_under_panic: ... kernel BUG at net/core/skbuff.c:214! Call Trace: skb_push (net/core/skbuff.c:2648) iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82) gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920) udp_queue_rcv_one_skb (net/ipv4/udp.c:2388) ... Kernel panic - not syncing: Fatal exception in interrupt

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.