CVE-2025-23018

NameCVE-2025-23018
DescriptionIPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof and route arbitrary traffic via an exposed network interface. This is a similar issue to CVE-2020-10136.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

NOT-FOR-US: IP tunnel protocol issue
https://papers.mathyvanhoef.com/usenix2025-tunnels.pdf
https://github.com/vanhoefm/tunneltester
https://www.top10vpn.com/research/tunneling-protocol-vulnerability/
https://kb.cert.org/vuls/id/199397
https://www.openwall.com/lists/oss-security/2025/01/21/10

Search for package or bug name: Reporting problems