Description
In the Linux kernel, the following vulnerability has been resolved:

net: cap advertised IP tunnel headroom

IP tunnel devices derive their advertised needed_headroom from lower
output devices. A stack of user-created devices can make the derived
value larger than the 16-bit skb header offsets can represent. Once IP
output reserves it, skb head expansion can wrap those offsets.

The runtime transmit path already caps a growing needed_headroom at 512.
Apply the same cap when tunnel configuration publishes needed_headroom
derived from a lower output device.

Capping the advertised value is safe: IP tunnel transmit still expands
the skb when a packet needs more headroom. A nonsensical stacked
configuration can therefore incur an extra reallocation, but it cannot
publish an unbounded reservation to upper layers.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Headroom Calculation
Action: Apply Fix
AI Analysis

Impact

The Linux kernel advertises the amount of socket‑buffer headroom that an IP tunnel device requires by deriving the value from the underlying output device. When multiple user‑created IP tunnel layers are stacked, the calculated value can exceed the 16‑bit limits that socket‑buffer header offsets can represent, causing those offsets to wrap. The runtime transmit path already limits an expanding needed_headroom to 512 bytes, and the patch applies the same cap to the advertised value. As a result the kernel will still expand the socket buffer if a packet needs more headroom, but the advertised value will never describe an unbounded reservation. The effect is that very deep tunnel stacks may trigger extra reallocations, potentially degrading performance, but they do not lead to memory corruption or direct control‑flow exploitation.

Affected Systems

All Linux kernels that lack the commit that caps advertised IP tunnel headroom are affected. The fix is included in all subsequent releases following the commit referenced in the verification links. Systems running an unpatched kernel on which users can create nested IP tunnel devices of arbitrary depth are impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% shows that the likelihood of exploitation is very low. The vulnerability is not currently listed in the CISA KEV catalog. An attacker would need the ability to configure nested IP tunnels on the target; by stacking many layers the attacker could trigger the headroom wrap, resulting in repeated reallocations and possible performance degradation. Because the patch caps the advertised value, no unsafe memory reservation or overflow can occur, and the risk of denial of service or memory corruption is mitigated.

Generated by OpenCVE AI on September 21, 2026 at 03:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that caps advertised IP tunnel headroom, such as upgrading to a kernel release from the commit 6b222adeb9340306e2ff97127c76117abb9b3df8.
  • If an upgrade is not immediately possible, configure IP tunnels to enforce a maximum headroom of 512 bytes via the device’s configuration options.
  • Audit and simplify any nested IP tunnel configurations to reduce the depth of the stack, minimizing the need for repeated reallocations.

Generated by OpenCVE AI on September 21, 2026 at 03:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: cap advertised IP tunnel headroom IP tunnel devices derive their advertised needed_headroom from lower output devices. A stack of user-created devices can make the derived value larger than the 16-bit skb header offsets can represent. Once IP output reserves it, skb head expansion can wrap those offsets. The runtime transmit path already caps a growing needed_headroom at 512. Apply the same cap when tunnel configuration publishes needed_headroom derived from a lower output device. Capping the advertised value is safe: IP tunnel transmit still expands the skb when a packet needs more headroom. A nonsensical stacked configuration can therefore incur an extra reallocation, but it cannot publish an unbounded reservation to upper layers.
Title net: cap advertised IP tunnel headroom
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:23.543Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80978

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:04.143

Modified: 2026-09-14T13:18:52.650

Link: CVE-2026-80978

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:39Z

Links: CVE-2026-80978 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:45:08Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound