The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.
https://usn.ubuntu.com/3754-1/
https://source.android.com/security/bulletin/2017-09-01
http://www.securitytracker.com/id/1037794
http://www.securityfocus.com/bid/96037