AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-64577

HIGH · CVSS 7.5 EPSS 0.54%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the GTP (GPRS Tunneling Protocol) implementation, specifically in the handling of echo responses where the function `gtp1u_send_echo_resp()` fails to check the return value of `skb_pull_data()`. This oversight can lead to a kernel panic when processing malformed packets, potentially causing denial of service. Organizations relying on Linux systems that utilize GTP should prioritize patching this vulnerability to maintain system stability and prevent service interruptions.

CVE
CVE-2026-64577
Severity
HIGH
CVSS
7.5
EPSS
0.54%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr + gtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For a 16-19 byte echo request the pull fails and returns NULL without advancing skb->data; execution continues, and the following skb_push() plus the IP header pushed by iptunnel_xmit() move skb->data below skb->head, tripping skb_under_panic(). Fix it by dropping the packet when skb_pull_data() fails. skbuff: skb_under_panic: ... kernel BUG at net/core/skbuff.c:214! Call Trace: skb_push (net/core/skbuff.c:2648) iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82) gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920) udp_queue_rcv_one_skb (net/ipv4/udp.c:2388) ... Kernel panic - not syncing: Fatal exception in interrupt