Out-of-bounds write in Linux kernel - CVE-2026-80725
Published: August 31, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in skb_gro_receive() and IPv6 GRO completion handling when processing crafted packets for BIG TCP aggregation beyond 64KB. A local user can inject specially crafted frames to cause memory corruption.
Exploitation requires access to inject crafted frames through AF_PACKET, and the issue is limited to older stable branches rather than mainline 7.0 and later.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-80725
linux (Debian package) - update to 6.12.107-1
External References
- https://git.kernel.org/stable/c/03cb8cc2961f5f781d12e903782cb3815ed84b1c
- https://git.kernel.org/stable/c/37a5dcd6837fc2afc44a7bc3ed8af4e983783d46
- https://git.kernel.org/stable/c/3ce832e2bd431d0c12ba525ed73ad8fbc4191da5
- https://git.kernel.org/stable/c/81be30c1f5f2bffda1f04c0efd0746af10b9643a
- https://git.kernel.org/stable/c/e907bf694ed55bdfe421be99dba35751a655df25