Linux vulnerability

In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which call iptunnel_xmit_stats(). iptunnel_xmit_stats() was assuming tunnels were only using NETDEV_PCPU_STAT_TSTATS. @syncp offset in pcpu_sw_netstats and pcpu_dstats is different. 32bit kernels would either have corruptions or freezes if the syncp sequence was overwritten. This patch also moves pcpu_stat_type closer to dev->{t,d}stats to avoid a potential cache line miss since iptunnel_xmit_stats() needs to read it.

Published 3 Apr 2026Updated 7 Sep 20264 sources
CVSS 8.2

What happened

In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which call iptunnel_xmit_stats(). iptunnel_xmit_stats() was assuming tunnels were only using NETDEV_PCPU_STAT_TSTATS. @syncp offset in pcpu_sw_netstats and pcpu_dstats is different. 32bit kernels would either have corruptions or freezes if the syncp sequence was overwritten. This patch also moves pcpu_stat_type closer to dev->{t,d}stats to avoid a potential cache line miss since iptunnel_xmit_stats() needs to read it.

Affected versions

Linux: cb1c1f3b7ef908408064734fb6bdaf5811b8b84c through before e40e2d11ced8119d3e4469ebe91264bc1cf71530 (git); be226352e8dc77d3313c096b2d8e7f69bf6980fc through before 5d562153b4719234227f99c2fb529f98a6a44d15 (git); be226352e8dc77d3313c096b2d8e7f69bf6980fc through before 0d087d00161f562d5047cc4009bb0c6a19daf9f1 (git); be226352e8dc77d3313c096b2d8e7f69bf6980fc through before 8431c602f551549f082bbfa67f3003f2d8e3e132 (git); 1db9041e91ac574f1cecc0e98e69ac35832e8088 (git); 6.6.153 through before 6.7 (semver); 6.14 Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.