CVE-2026-97984 PUBLISHED

net: ipv6: Fix UDP length overflow with PMTU discover and big MTU

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

net: ipv6: Fix UDP length overflow with PMTU discover and big MTU

This commit bounds cork->base.fragsize to IP6_MAX_MTU for UDP sockets to avoid a possible overflow of UDP length that triggers a WARN in udp_set_len_short when setsockopt IPV6_MTU_DISCOVER is set to IPV6_PMTUDISC_DO or IPV6_PMTUDISC_PROBE, and a large packet is sent over a netdev with an unusually large MTU.

Steps to reproduce (included in the new selftest):

  1. Set device MTU bigger than IP6_MAX_MTU. cork->base.fragsize will be set to that MTU in ip6_setup_cork.
  2. Set IPV6_MTU_DISCOVER to IPV6_PMTUDISC_PROBE or IPV6_PMTUDISC_DO. It lets maxnonfragsize be set to device MTU (cork->fragsize) in __ip6_append_data, rather than to IP6_MAX_MTU.
  3. Send 65528 bytes of payload (+8 bytes of UDP header, +40 bytes of IPv6 header). Device MTU allows it (it's only one byte bigger than IP6_MAX_MTU, and the device MTU is bigger than that).
  4. The UDP length in the built packet is 65536, which overflows the 16-bit length field and triggers the WARN in udp_set_len_short.

To avoid breaking sending UDP jumbograms over raw IPv6 sockets, limit the change to UDP sockets only.

The original overflow bug with IPv6 and IPV6_PMTUDISC_DO seems to predate git history (verified reproduction on 2.6.21), was fixed later, and then reappeared in commit 427faee167bc ("net: ipv6: introduce ip6_dst_mtu_maybe_forward"), which is chosen as the Fixes tag here. The overflow with IPV6_PMTUDISC_PROBE reproduces since its introduction in commit 628a5c561890 ("[INET]: Add IP(V6)_PMTUDISC_RPOBE").

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 427faee167bce4ccb0b22f6815a9ac509e31d4c3 to 1d56a00ec91f2885c64ea5b8cea18cb746b91bbb (excl.)
  • affected from 427faee167bce4ccb0b22f6815a9ac509e31d4c3 to ce66352d3eb21825410af8b91db7cc4bb8e22c98 (excl.)
  • affected from 427faee167bce4ccb0b22f6815a9ac509e31d4c3 to e01b7c176d9af2b7c22bb3fe12cf9a7904f99fdc (excl.)
  • affected from 427faee167bce4ccb0b22f6815a9ac509e31d4c3 to 0ae10b6be49b425827659b23bcce498f80eb7182 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.15 is affected
  • unaffected from 0 to 5.15 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc3 to * (incl.)

References