Linux Kernel BIG TCP IPv6 Extension Header Offload Vulnerability

Vulnerability

A vulnerability in the Linux kernel's handling of BIG TCP packets over IPv6 has been addressed. The issue arose because the kernel disabled hardware offload for IPv6 packets with extension headers on devices that support IPv6 checksum offload. This change led to warnings about bad offload for BIG TCP packets, which use an extension header to indicate packet length. The vulnerability specifically affected devices with BIG TCP TCP Segmentation Offload (TSO) enabled, where the extension header is present for packet capture but not transmitted over the network.

Impact

The vulnerability could cause incorrect packet processing, leading to performance issues or dropped packets for applications relying on BIG TCP over IPv6.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.0
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.