LiveActive security incident?Get immediate response
CVE Record

CVE-2025-71098: ip6_gre: make ip6gre_header() robust

In the Linux kernel, the following vulnerability has been resolved: ip6_gre: make ip6gre_header() robust Over the years, syzbot found many ways to crash the kernel in ip6gre_header() [1]. This involves team or bonding drivers ability to dynamically change their dev->needed_headroom and/or dev->hard_header_len In this particular crash mld_newpack() allocated an skb with a too small reserve/headroom, and by the time mld_sendpack() was called, syzbot managed to attach an ip6gre device. [1] skbuff: skb_under_panic: text:ffffffff8a1d69a8 len:136 put:40 head:ffff888059bc7000 data:ffff888059bc6fe8 tail:0x70 end:0x6c0 dev:team0 ------------[ cut here ]------------ kernel BUG at net/core/skbuff.c:213 ! <TASK> skb_under_panic net/core/skbuff.c:223 [inline] skb_push+0xc3/0xe0 net/core/skbuff.c:2641 ip6gre_header+0xc8/0x790 net/ipv6/ip6_gre.c:1371 dev_hard_header include/linux/netdevice.h:3436 [inline] neigh_connected_output+0x286/0x460 net/core/neighbour.c:1618 neigh_output include/net/neighbour.h:556 [inline] ip6_finish_output2+0xfb3/0x1480 net/ipv6/ip6_output.c:136 __ip6_finish_output net/ipv6/ip6_output.c:-1 [inline] ip6_finish_output+0x234/0x7d0 net/ipv6/ip6_output.c:220 NF_HOOK_COND include/linux/netfilter.h:307 [inline] ip6_output+0x340/0x550 net/ipv6/ip6_output.c:247 NF_HOOK+0x9e/0x380 include/linux/netfilter.h:318 mld_sendpack+0x8d4/0xe60 net/ipv6/mcast.c:1855 mld_send_cr net/ipv6/mcast.c:2154 [inline] mld_ifc_work+0x83e/0xd60 net/ipv6/mcast.c:2693

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This Linux kernel issue can crash the system in IPv6 GRE packet handling when network device header sizes change unexpectedly. The public record describes a robustness fix, not data theft or privilege escalation. Business risk is mainly availability for affected Linux systems, especially appliances or hosts using relevant networking features.

Executive priority

Treat as a kernel availability issue requiring normal vulnerability management urgency. Prioritize internet-facing, critical, or appliance-like Linux systems after confirming affected kernel exposure. Escalate if vendor advisories rate a specific product higher.

Technical view

CVE-2025-71098 is a Linux kernel ip6_gre flaw in ip6gre_header(). A too-small skb headroom during MLD packet handling can lead to skb_under_panic and a kernel BUG. The record links stable kernel commits that make the header path robust against changed needed_headroom or hard_header_len.

Likely exposure

Exposure depends on running affected Linux kernel versions and reachable configurations involving IPv6 GRE with team or bonding device behavior. The bundle lists Linux as affected across multiple kernel series but does not provide distribution-specific package names or full product impact.

Exploitation context

The source describes syzbot finding crash paths and this specific crash scenario. There is no KEV listing and no cited evidence of active exploitation. The provided material does not establish remote exploitability, required privileges, or a public weaponized exploit.

Researcher notes

The public record is crash-oriented and lacks CVSS, CWE, privilege, attack-vector, and complete product mapping. Validation should focus on kernel provenance, backport evidence, and whether local configurations can reach the described ip6_gre and MLD path.

Mitigation direction

  • Apply kernel vendor updates containing the listed ip6_gre stable fixes.
  • Track Linux distribution advisories for backported CVE-2025-71098 packages.
  • For Siemens products, follow SSA-019113 guidance and update status.
  • If updates are unavailable, request vendor-supported mitigations for exposed systems.

Validation and detection

  • Inventory Linux kernel versions against affected and fixed vendor package advisories.
  • Identify systems using IPv6 GRE, team, or bonding network configurations.
  • Confirm installed kernels include one of the referenced stable fixes or vendor backports.
  • Review crash logs for skb_under_panic or ip6gre_header stack traces.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2025-71098 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
9Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
siemens-SADPADP container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxc12b395a46646bab69089ce7016ac78177f6001f, c12b395a46646bab69089ce7016ac78177f6001f, c12b395a46646bab69089ce7016ac78177f6001f, c12b395a46646bab69089ce7016ac78177f6001f, c12b395a46646bab69089ce7016ac78177f6001f, c12b395a46646bab69089ce7016ac78177f6001f, c12b395a46646bab69089ce7016ac78177f6001funaffected
LinuxLinux3.7, 0, 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.64, 6.18.4, 6.19affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.