Impact
The issue occurs when the function that checks for Path MTU Discovery on IP tunnels is invoked while the socket buffer’s transport header has not yet been initialized. In that condition the function treats the uninitialized transport header as an offset, which resolves to the maximum unsigned value of a 16‑bit number. As a result, the code attempts to read beyond the end of the packet’s data, resulting in an out‑of‑bounds read of the ICMP header. The applied fix removes the assumption that the transport header is set and adds a bounds check by accessing the ICMP header based on the IPv4 network header and ensuring it lies within the linear part of the packet.
Affected Systems
Every Linux kernel build that still contains the original iptunnel_pmtud_check_icmp() logic is affected. The CPE list includes the generic Linux kernel as well as the 7.1 release candidates from rc1 through rc5. Distributions shipping any of those upstream kernels without the referenced commits are at risk until they update to a kernel that incorporates the fix.
Risk and Exploitability
The CVSS score of 9.1 points to a high‑impact vulnerability, yet the EPSS score is below 1%, indicating that exploitation attempts are very rare. The vulnerability is not part of the CISA KEV catalog. The likely attack vector is remote network delivery of specially crafted ICMP packets, inferred because the vulnerability is triggered by incoming packets processed by iptunnel_pmtud_check_icmp() on tunnel interfaces. By doing so, an attacker could read kernel memory contents, potentially leaking sensitive data. The attack does not require local privileges; it is limited to information disclosure rather than a crash or denial of service.
OpenCVE Enrichment
Ubuntu USN