Description
In the Linux kernel, the following vulnerability has been resolved:

ipvlan: inherit needed_headroom and needed_tailroom from phy_dev

ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),
but leave needed_headroom and needed_tailroom set to 0.

When the underlying phy_dev (or stacked lower device) requires extra headroom
or tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or
veth with rx headroom), upper layers calculating packet headroom and tailroom
fail to reserve sufficient space.

This can result in reallocation overhead, skb headroom underflows, or KASAN
slab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header()
prepends header data or when lower devices append tailroom.

Fix this by:
1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init().
2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans
in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.
Published: 2026-08-26
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises when the Linux kernel’s ipvlan driver fails to propagate the needed_headroom and needed_tailroom values from the underlying physical device. As a result, packet processing routines that rely on accurate headroom and tailroom calculations can overrun buffers when preparing headers or appending trailers. The ensuing memory corruption can trigger KASAN slab‑use‑after‑free crashes, excessive reallocations, or headroom underflow errors, which typically culminate in kernel panics or loss of network service.

Affected Systems

The flaw is present in all Linux kernel releases that contain the ipvlan networking module and have not been updated to a version where ipvlan_init correctly copies needed_headroom and needed_tailroom from the physical device. Therefore any host running a kernel with active ipvlan support—whether in a standard distribution kernel or a custom build—may be affected.

Risk and Exploitability

A CVSS score has not been published, and the EPSS metric is unavailable, so the quantitative likelihood of exploitation is unknown. Nonetheless, the potential for a fatal kernel crash indicates a high severity from an availability perspective. The code path that miscalculates headroom is exercised during packet processing, so it is inferred that an attacker with network or local access could craft traffic to an affected ipvlan interface to trigger the flaw, possibly leading to denial‑of‑service or repeated crashes. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog.

Generated by OpenCVE AI on August 26, 2026 at 15:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the system kernel to a release that includes the patch where ipvlan_init copies needed_headroom and needed_tailroom from the physical device.
  • If an upgrade is not feasible, disable ipvlan networking by removing the CONFIG_IPVLAN driver or setting the interface to a non‑ipvlan type to prevent the faulty code from running.
  • Continuously monitor system logs for Oops, KASAN, or packet headroom underflow messages to detect exploitation attempts.

Generated by OpenCVE AI on August 26, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Wed, 26 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(), but leave needed_headroom and needed_tailroom set to 0. When the underlying phy_dev (or stacked lower device) requires extra headroom or tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx headroom), upper layers calculating packet headroom and tailroom fail to reserve sufficient space. This can result in reallocation overhead, skb headroom underflows, or KASAN slab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header() prepends header data or when lower devices append tailroom. Fix this by: 1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init(). 2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.
Title ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-26T14:36:54.773Z

Reserved: 2026-08-15T05:44:03.931Z

Link: CVE-2026-74744

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T15:16:53.250

Modified: 2026-08-26T15:16:53.250

Link: CVE-2026-74744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T16:00:07Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow