LiveActive security incident?Get immediate response
CVE Record

CVE-2022-50816: ipv6: ensure sane device mtu in tunnels

In the Linux kernel, the following vulnerability has been resolved: ipv6: ensure sane device mtu in tunnels Another syzbot report [1] with no reproducer hints at a bug in ip6_gre tunnel (dev:ip6gretap0) Since ipv6 mcast code makes sure to read dev->mtu once and applies a sanity check on it (see commit b9b312a7a451 "ipv6: mcast: better catch silly mtu values"), a remaining possibility is that a layer is able to set dev->mtu to an underflowed value (high order bit set). This could happen indeed in ip6gre_tnl_link_config_route(), ip6_tnl_link_config() and ipip6_tunnel_bind_dev() Make sure to sanitize mtu value in a local variable before it is written once on dev->mtu, as lockless readers could catch wrong temporary value. [1] skbuff: skb_over_panic: text:ffff80000b7a2f38 len:40 put:40 head:ffff000149dcf200 data:ffff000149dcf2b0 tail:0xd8 end:0xc0 dev:ip6gretap0 ------------[ cut here ]------------ kernel BUG at net/core/skbuff.c:120 Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP Modules linked in: CPU: 1 PID: 10241 Comm: kworker/1:1 Not tainted 6.0.0-rc7-syzkaller-18095-gbbed346d5a96 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/30/2022 Workqueue: mld mld_ifc_work pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : skb_panic+0x4c/0x50 net/core/skbuff.c:116 lr : skb_panic+0x4c/0x50 net/core/skbuff.c:116 sp : ffff800020dd3b60 x29: ffff800020dd3b70 x28: 0000000000000000 x27: ffff00010df2a800 x26: 00000000000000c0 x25: 00000000000000b0 x24: ffff000149dcf200 x23: 00000000000000c0 x22: 00000000000000d8 x21: ffff80000b7a2f38 x20: ffff00014c2f7800 x19: 0000000000000028 x18: 00000000000001a9 x17: 0000000000000000 x16: ffff80000db49158 x15: ffff000113bf1a80 x14: 0000000000000000 x13: 00000000ffffffff x12: ffff000113bf1a80 x11: ff808000081c0d5c x10: 0000000000000000 x9 : 73f125dc5c63ba00 x8 : 73f125dc5c63ba00 x7 : ffff800008161d1c x6 : 0000000000000000 x5 : 0000000000000080 x4 : 0000000000000001 x3 : 0000000000000000 x2 : ffff0001fefddcd0 x1 : 0000000100000000 x0 : 0000000000000089 Call trace: skb_panic+0x4c/0x50 net/core/skbuff.c:116 skb_over_panic net/core/skbuff.c:125 [inline] skb_put+0xd4/0xdc net/core/skbuff.c:2049 ip6_mc_hdr net/ipv6/mcast.c:1714 [inline] mld_newpack+0x14c/0x270 net/ipv6/mcast.c:1765 add_grhead net/ipv6/mcast.c:1851 [inline] add_grec+0xa20/0xae0 net/ipv6/mcast.c:1989 mld_send_cr+0x438/0x5a8 net/ipv6/mcast.c:2115 mld_ifc_work+0x38/0x290 net/ipv6/mcast.c:2653 process_one_work+0x2d8/0x504 kernel/workqueue.c:2289 worker_thread+0x340/0x610 kernel/workqueue.c:2436 kthread+0x12c/0x158 kernel/kthread.c:376 ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860 Code: 91011400 aa0803e1 a90027ea 94373093 (d4210000)

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2022-50816 is a Linux kernel bug in IPv6 tunnel MTU handling. Under certain tunnel conditions, the kernel could store an invalid MTU value and later crash during IPv6 multicast processing. Business impact is most likely availability risk on affected Linux systems, especially those using IPv6 GRE or IPIP6 tunneling.

Executive priority

Treat as a targeted availability patching issue, not an emergency internet-wide threat based on current evidence. Prioritize tunnel-heavy infrastructure, cloud networking nodes, VPN gateways, and hosts where a kernel crash would create service disruption.

Technical view

The fix sanitizes MTU values before writing to dev->mtu in ip6gre_tnl_link_config_route(), ip6_tnl_link_config(), and ipip6_tunnel_bind_dev(). The reported failure was a syzbot kernel BUG involving ip6gretap0 and skb_over_panic during MLD multicast packet construction. The CVE record does not provide CVSS, CWE, or a reproducer.

Likely exposure

Exposure is limited to Linux kernels in affected stable lines, particularly systems using IPv6 tunnel devices such as ip6_gre, ip6gretap, or IPIP6. The source lists fixes across stable branches including 4.14.305, 4.19.272, 5.4.231, 5.10.153, 5.15.77, 6.0.7, and 6.1.

Exploitation context

No active exploitation is indicated; the CVE is not listed as KEV. The report came from syzbot and explicitly notes no reproducer hints. Preconditions are incomplete, but the bug involves tunnel MTU configuration and lockless readers observing a bad temporary MTU value.

Researcher notes

Evidence supports a kernel crash class issue caused by underflowed or otherwise invalid tunnel MTU values. Public data does not establish privilege requirements, remote reachability, or reliable exploitability. Avoid assuming exploitability beyond the syzbot-triggered crash path unless distribution advisories add detail.

Mitigation direction

  • Upgrade to a vendor kernel containing the referenced stable fixes.
  • Prioritize systems using IPv6 GRE, ip6gretap, or IPIP6 tunnels.
  • If unable to patch, check Linux distribution guidance for supported mitigations.
  • Track kernel package advisories for backported fixes, not only version numbers.

Validation and detection

  • Inventory Linux systems and running kernel versions.
  • Identify hosts with IPv6 tunnel interfaces or related modules enabled.
  • Compare kernel packages against distribution advisories and fixed stable releases.
  • Confirm the applied kernel includes one of the referenced upstream fixes.
  • Monitor for kernel BUG or skb_over_panic messages involving IPv6 multicast tunnels.
Prepared
Confidence
medium
Sources
9

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-50816 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
8Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxc12b395a46646bab69089ce7016ac78177f6001f, c12b395a46646bab69089ce7016ac78177f6001f, c12b395a46646bab69089ce7016ac78177f6001f, c12b395a46646bab69089ce7016ac78177f6001f, c12b395a46646bab69089ce7016ac78177f6001f, c12b395a46646bab69089ce7016ac78177f6001f, c12b395a46646bab69089ce7016ac78177f6001funaffected
LinuxLinux3.7, 0, 4.14.305, 4.19.272, 5.4.231, 5.10.153, 5.15.77, 6.0.7, 6.1affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.