---
id: CVE-2024-26665
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  tunnels: fix out of bounds access when building IPv6 PMTU error

  If the ICMPv6 error is built from a non-linear skb we get the following
  splat,

    BUG: KASAN: slab-out-…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  tunnels: fix out of bounds access when building IPv6 PMTU error

  If the ICMPv6 error is built from a non-linear skb we get the following
  splat,

    BUG: KASAN: slab-out-…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-125
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.9, < 5.10.210'
  - 'linux_kernel >= 5.11, < 5.15.149'
  - 'linux_kernel >= 5.16, < 6.1.78'
  - 'linux_kernel >= 6.2, < 6.6.17'
  - 'linux_kernel >= 6.7, < 6.7.5'
  - linux_kernel = 6.8
  - debian_linux = 10.0
patched:
  - linux_kernel 6.7.5
published: '2024-04-02'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-26665'
references:
  - url: 'https://git.kernel.org/stable/c/510c869ffa4068c5f19ff4df51d1e2f3a30aaac1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7dc9feb8b1705cf00de20563b6bc4831f4c99dab'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d75abeec401f8c86b470e7028a13fcdc87e5dd06'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d964dd1bc1452594b4207d9229c157d9386e5d8a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e37cde7a5716466ff2a76f7f27f0a29b05b9a732'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e77bf828f1ca1c47fcff58bdc26b60a9d3dfbe1d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/510c869ffa4068c5f19ff4df51d1e2f3a30aaac1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/7dc9feb8b1705cf00de20563b6bc4831f4c99dab'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/d75abeec401f8c86b470e7028a13fcdc87e5dd06'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/d964dd1bc1452594b4207d9229c157d9386e5d8a'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/e37cde7a5716466ff2a76f7f27f0a29b05b9a732'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/e77bf828f1ca1c47fcff58bdc26b60a9d3dfbe1d'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00679
epssPercentile: 0.50284
ingestedAt: '2026-08-05T10:46:47.861Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

tunnels: fix out of bounds access when building IPv6 PMTU error

If the ICMPv6 error is built from a non-linear skb we get the following
splat,

  BUG: KASAN: slab-out-of-bounds in do_csum+0x220/0x240
  Read of size 4 at addr ffff88811d402c80 by task netperf/820
  CPU: 0 PID: 820 Comm: netperf Not tainted 6.8.0-rc1+ #543
  ...
   kasan_report+0xd8/0x110
   do_csum+0x220/0x240
   csum_partial+0xc/0x20
   skb_tunnel_check_pmtu+0xeb9/0x3280
   vxlan_xmit_one+0x14c2/0x4080
   vxlan_xmit+0xf61/0x5c00
   dev_hard_start_xmit+0xfb/0x510
   __dev_queue_xmit+0x7cd/0x32a0
   br_dev_queue_push_xmit+0x39d/0x6a0

Use skb_checksum instead of csum_partial who cannot deal with non-linear
SKBs.

## Affected

- `linux_kernel >= 5.9, < 5.10.210`
- `linux_kernel >= 5.11, < 5.15.149`
- `linux_kernel >= 5.16, < 6.1.78`
- `linux_kernel >= 6.2, < 6.6.17`
- `linux_kernel >= 6.7, < 6.7.5`
- `linux_kernel = 6.8`
- `debian_linux = 10.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.7.5`
