Impact
The Linux kernel advertises the amount of socket‑buffer headroom that an IP tunnel device requires by deriving the value from the underlying output device. When multiple user‑created IP tunnel layers are stacked, the calculated value can exceed the 16‑bit limits that socket‑buffer header offsets can represent, causing those offsets to wrap. The runtime transmit path already limits an expanding needed_headroom to 512 bytes, and the patch applies the same cap to the advertised value. As a result the kernel will still expand the socket buffer if a packet needs more headroom, but the advertised value will never describe an unbounded reservation. The effect is that very deep tunnel stacks may trigger extra reallocations, potentially degrading performance, but they do not lead to memory corruption or direct control‑flow exploitation.
Affected Systems
All Linux kernels that lack the commit that caps advertised IP tunnel headroom are affected. The fix is included in all subsequent releases following the commit referenced in the verification links. Systems running an unpatched kernel on which users can create nested IP tunnel devices of arbitrary depth are impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% shows that the likelihood of exploitation is very low. The vulnerability is not currently listed in the CISA KEV catalog. An attacker would need the ability to configure nested IP tunnels on the target; by stacking many layers the attacker could trigger the headroom wrap, resulting in repeated reallocations and possible performance degradation. Because the patch caps the advertised value, no unsafe memory reservation or overflow can occur, and the risk of denial of service or memory corruption is mitigated.
OpenCVE Enrichment
Debian DSA