Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64577

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
05/08/2026
Última modificación:
05/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> gtp: check skb_pull_data() return in gtp1u_send_echo_resp()<br /> <br /> gtp1u_send_echo_resp() ignores skb_pull_data()&amp;#39;s return value. Its<br /> caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +<br /> gtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For<br /> a 16-19 byte echo request the pull fails and returns NULL without<br /> advancing skb-&gt;data; execution continues, and the following skb_push()<br /> plus the IP header pushed by iptunnel_xmit() move skb-&gt;data below<br /> skb-&gt;head, tripping skb_under_panic().<br /> <br /> Fix it by dropping the packet when skb_pull_data() fails.<br /> <br /> skbuff: skb_under_panic: ...<br /> kernel BUG at net/core/skbuff.c:214!<br /> Call Trace:<br /> skb_push (net/core/skbuff.c:2648)<br /> iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)<br /> gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)<br /> udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)<br /> ...<br /> Kernel panic - not syncing: Fatal exception in interrupt

Impacto