Back

HIGH

ipv6: Fix out-of-bounds access in ipv6_find_tlv()

Published Oct 22, 2025

Description

optlen is fetched without checking whether there is more than one byte to parse. It can lead to out-of-bounds access.

Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.

Affected products

Remediation

Red Hat statement

The function ipv6_find_tlv() parsed IPv6 extension headers without checking that at least two bytes were available before reading the option length field. An attacker could send a malformed IPv6 packet with a truncated extension header, causing an out-of-bounds read and potential kernel crash or memory fault while parsing. The fix adds a length check (if (len < 2) goto bad;) before accessing the second byte, preventing buffer overrun. This issue is remotely triggerable via network traffic and can lead to kernel panic (DoS) or, in rare cases, information leakage through speculative execution paths.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (14)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Oct 22, 2025
Updated Aug 5, 2026
Reserved Oct 22, 2025

CISA Vulnrichment

No data

NVD

Status Deferred
Modified Aug 4, 2026

Red Hat

Severity Moderate
Public date Oct 22, 2025
Bugzilla 2405713

ENISA EUVD

Assigner Linux
Published Oct 22, 2025
Updated Aug 5, 2026

GitHub

No data