Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2022-50816 — kernel

⚪ Unknown ✅ No Known Exploit NVD
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

ipv6: ensure sane device mtu in tunnels

In the Linux kernel, the following vulnerability has been resolved:

ipv6: ensure sane device mtu in tunnels

Another syzbot report [1] with no reproducer hints

at a bug in ip6_gre tunnel (dev:ip6gretap0)

Since ipv6 mcast code makes sure to read dev->mtu once

and applies a sanity check on it (see commit b9b312a7a451

"ipv6: mcast: better catch silly mtu values"), a remaining

possibility is that a layer is able to set dev->mtu to

an underflowed value (high order bit set).

This could happen indeed in ip6gre_tnl_link_config_route(),

ip6_tnl_link_config() and ipip6_tunnel_bind_dev()

Make sure to sanitize mtu value in a local variable before

it is written once on dev->mtu, as lockless readers could

catch wrong temporary value.

[1]

skbuff: skb_over_panic: text:ffff80000b7a2f38 len:40 put:40 head:ffff000149dcf200 data:ffff000149dcf2b0 tail:0xd8 end:0xc0 dev:ip6gretap0

------------[ cut here ]------------

kernel BUG at net/core/skbuff.c:120

Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP

Modules linked in:

CPU: 1 PID: 10241 Comm: kworker/1:1 Not tainted 6.0.0-rc7-syzkaller-18095-gbbed346d5a96 #0

Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/30/2022

Workqueue: mld mld_ifc_work

pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)

pc : skb_panic+0x4c/0x50 net/core/skbuff.c:116

lr : skb_panic+0x4c/0x50 net/core/skbuff.c:116

sp : ffff800020dd3b60

x29: ffff800020dd3b70 x28: 0000000000000000 x27: ffff00010df2a800

x26: 00000000000000c0 x25: 00000000000000b0 x24: ffff000149dcf200

x23: 00000000000000c0 x22: 00000000000000d8 x21: ffff80000b7a2f38

x20: ffff00014c2f7800 x19: 0000000000000028 x18: 00000000000001a9

x17: 0000000000000000 x16: ffff80000db49158 x15: ffff000113bf1a80

x14: 0000000000000000 x13: 00000000ffffffff x12: ffff000113bf1a80

x11: ff808000081c0d5c x10: 0000000000000000 x9 : 73f125dc5c63ba00

x8 : 73f125dc5c63ba00 x7 : ffff800008161d1c x6 : 0000000000000000

x5 : 0000000000000080 x4 : 0000000000000001 x3 : 0000000000000000

x2 : ffff0001fefddcd0 x1 : 0000000100000000 x0 : 0000000000000089

Call trace:

skb_panic+0x4c/0x50 net/core/skbuff.c:116

skb_over_panic net/core/skbuff.c:125 [inline]

skb_put+0xd4/0xdc net/core/skbuff.c:2049

ip6_mc_hdr net/ipv6/mcast.c:1714 [inline]

mld_newpack+0x14c/0x270 net/ipv6/mcast.c:1765

add_grhead net/ipv6/mcast.c:1851 [inline]

add_grec+0xa20/0xae0 net/ipv6/mcast.c:1989

mld_send_cr+0x438/0x5a8 net/ipv6/mcast.c:2115

mld_ifc_work+0x38/0x290 net/ipv6/mcast.c:2653

process_one_work+0x2d8/0x504 kernel/workqueue.c:2289

worker_thread+0x340/0x610 kernel/workqueue.c:2436

kthread+0x12c/0x158 kernel/kthread.c:376

ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860

Code: 91011400 aa0803e1 a90027ea 94373093 (d4210000)

Affected software

CVE-2022-50816 is recorded against 2 packages.

  • kernel (from 5.16.0 up to 6.0.7)
  • unknown

Timeline and source

Published on 30 December 2025 and last revised on 12 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

Other advisories for this package

kernel has other advisories on record. If you are patching this one, these are worth checking on the same host:

CVE-2022-50816 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2025-12-30
Updated 2026-08-20
Modified 2026-08-12
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 5.16.0 6.0.7
unknown

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2022-50816?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2022-50816 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2022