Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-80725

net: gro: properly validate BIG TCP aggregation criteria
Back to all
CVE

CVE-2026-80725

net: gro: properly validate BIG TCP aggregation criteria

In the Linux kernel, the following vulnerability has been resolved:

net: gro: properly validate BIG TCP aggregation criteria

When GRO attempts to aggregate packets beyond GROLEGACYMAX_SIZE (64KB),

BIG TCP should only be permitted for plain IPv4 TCP and plain IPv6 TCP

(with sufficient MAC header room to insert the temporary HBH jumbo header).

However, commit b1a78b9b9886 ("net: add support for ipv4 big tcp")

loosened the check in skbgroreceive(), leading to several issues:

  1. skbgroreceive() checked skb_headroom(p) instead of the actual space

   before the MAC header (p->macheader). Because skbheadroom(p) includes

   maclen, crafted frames (e.g. injected via AFPACKET) can pass the check

   with p->macheader < 8 bytes. When ipv6gro_complete() inserts the

   temporary HBH jumbo header, the memmove() starts before skb->head,

   causing an out-of-bounds write and wrapping skb->mac_header.

  1. It allowed non-IP protocols such as software VLAN (ETHP8021Q /

   ETHP8021AD) to aggregate beyond 64KB because

   p->protocol != ETHPIPV6 was true.

  1. It checked p->encapsulation instead of NAPIGROCB(skb)->encap_mark,

   allowing encapsulated flows (e.g. SIT / IPv6-in-IPv4) to aggregate

   beyond 64KB.

Fix skbgroreceive() to strictly enforce:

  • NAPIGROCB(skb)->proto == IPPROTO_TCP
  • Not encapsulated (!NAPIGROCB(skb)->encap_mark && !p->encapsulation)
  • Protocol must be either ETHPIP or ETHPIPV6
  • If ETHPIPV6, p->mac_header must be at least

  sizeof(struct hopjumbohdr)

Returning -E2BIG from skbgroreceive() ensures that packets which cannot

become BIG TCP are cleanly flushed at <= 64KB and delivered intact without

dropping.

This issue does not exist in mainline (7.0+) because the subsystem was

rewritten in commit 81be30c1f5f2 ("net/ipv6: Drop HBH for BIG TCP on RX

side"), making this fix relevant only for older stable branches like

6.18.y.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/03cb8cc2961f5f781d12e903782cb3815ed84b1c, https://git.kernel.org/stable/c/37a5dcd6837fc2afc44a7bc3ed8af4e983783d46, https://git.kernel.org/stable/c/3ce832e2bd431d0c12ba525ed73ad8fbc4191da5, https://git.kernel.org/stable/c/81be30c1f5f2bffda1f04c0efd0746af10b9643a, https://git.kernel.org/stable/c/e907bf694ed55bdfe421be99dba35751a655df25, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80725.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80725, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00671%
EPSS Percentile
0.50513%
Introduced Version
0fe79f28bfaf73b66b7b1562d2468f94aa03bd12,5.19.0,6.2.0,6.7.0,6.13.0,0
Fix Available
81be30c1f5f2bffda1f04c0efd0746af10b9643a,6.1.185,6.6.154,6.12.106,6.18.47,6.1.187-1,6.12.107-1~deb12u1,6.12.107-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek,1:6.1.186-228.374.amzn2023,1:1.0-0.amzn2023,1:6.18.48-107.148.amzn2023

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading