Impact
The Linux kernel bug causes the hard_header_len of NBMA GRE tunnels to incorrectly include the lower device’s hardware header length when header_ops is enabled. This miscalculation can lead to inaccurate header length values for ARPHRD_IP6GRE devices that use header_ops, while tap and erspan devices retain their fixed Ethernet header header calculation.
Affected Systems
Linux kernel versions that do not505b6d296c486ef7d1274f279d4c43a172f63224) are affected. Distributions shipping kernel releases prior to that commit, as well as custom kernel builds that enable header_ops for ARPHRD_IP6GRE devices without the patch, remain vulnerable.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity, while the EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low exploitation probability. The likely attack vector is traffic to a vulnerable interface, which could trigger the incorrect header calculation. No further exploitation method is documented beyond the incorrect header length handling.
OpenCVE Enrichment
Debian DSA