Back

CRITICAL

kernel: ip6_gre: Invalid reads in ip6gre_err

Published Mar 23, 2017

Description

The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 5 and 6 are not affected as they do not include this code. Red Hat Enterprise Linux 7, MRG and realtime kernels contain the code, but are not affected. At this time we do not believe there is a denial of service, memory leak, privilege escalation or trust barrier crossed. The kernel may attribute errors in system logs to the wrong tunnel. If you believe this is in error and have evidence or thoughts to the contrary please contact Red Hat Security Team.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 23, 2017
Updated Aug 5, 2024
Reserved Feb 7, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 5, 2017