cbcvebase.
CVE-2025-71085
published 2026-01-13

CVE-2025-71085: In the Linux kernel, the following vulnerability has been resolved: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() There exists a kernel…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() There exists a kernel oops caused by a BUG_ON(nhead INT_MAX (i.e. (int)(skb_headroom(skb) + len_delta) skb_headroom(skb)) is meant to ensure that delta = headroom - skb_headroom(skb) is never negative, otherwise we will trigger a BUG_ON in pskb_expand_head(). However, if headroom > INT_MAX and delta cmsg_len = cmsg_len; cmsg->cmsg_level = IPPROTO_IPV6; cmsg->cmsg_type = IPV6_HOPOPTS; char * hop_hdr = (char *)cmsg + sizeof(struct cmsghdr); hop_hdr[1] = 0x9; //set hop size - (0x9 + 1) * 8 = 80 sendmsg(fd, &msg, 0);

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 2917f57b6bc15cc6787496ee5f2fdf17f0e9b7d3 < 86f365897068d09418488165a68b23cb5baa37f286f365897068d09418488165a68b23cb5baa37f2
linuxlinux>= 2917f57b6bc15cc6787496ee5f2fdf17f0e9b7d3 < 6b7522424529556c9cbc15e15e7bd4eeae3109106b7522424529556c9cbc15e15e7bd4eeae310910
linuxlinux>= 2917f57b6bc15cc6787496ee5f2fdf17f0e9b7d3 < 2bb759062efa188ea5d07242a43e5aa5464bbae12bb759062efa188ea5d07242a43e5aa5464bbae1
linuxlinux>= 2917f57b6bc15cc6787496ee5f2fdf17f0e9b7d3 < c53aa6a5086f03f19564096ee084a202a8c738c0c53aa6a5086f03f19564096ee084a202a8c738c0
linuxlinux>= 2917f57b6bc15cc6787496ee5f2fdf17f0e9b7d3 < bf3709738d8a8cc6fa275773170c5c29511a0b24bf3709738d8a8cc6fa275773170c5c29511a0b24
linuxlinux>= 2917f57b6bc15cc6787496ee5f2fdf17f0e9b7d3 < 73744ad5696dce0e0f43872aba8de6a83d6ad57073744ad5696dce0e0f43872aba8de6a83d6ad570
linuxlinux>= 2917f57b6bc15cc6787496ee5f2fdf17f0e9b7d3 < 58fc7342b529803d3c221101102fe913df7adb8358fc7342b529803d3c221101102fe913df7adb83
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.5-16.18.5-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 4.8.0 < 5.10.2485.10.248

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.