Impact
In the Linux kernel, the tun_get_user function uses tun->align both as skb headroom and to determine how much packet data to keep linear. When an oversized headroom request is propagated, the calculation of SKB_MAX_HEAD(align) can underflow, producing a negative good_linear value. That value, when cast to an unsigned size_t, causes tun_alloc_skb() to place skb->data outside the allocated head area, leading to kernel memory corruption that can be exploited for arbitrary code execution or a system crash.
Affected Systems
The flaw resides in the net kernel. Any kernel build that contains the unpatched tun code is affected, regardless of distribution. The CPE string cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* indicates that all Linux kernel releases prior to the patch are vulnerable. This includes common distributions such as Ubuntu, Debian, Red Hat, SUSE, and others that ship vanilla kernel releases.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity. The EPSS score of <1 % suggests a low probability of active exploitation, and the flaw is not listed in the CISA KEV catalog, meaning no publicly known exploits exist yet. An attacker would typically need to influence a tun interface—often through a privileged or compromised network service or a tool like Open vSwitch—to trigger the underflow and cause kernel memory corruption. Despite the low exploitation likelihood, the kernel‑level impact warrants immediate remediation.
OpenCVE Enrichment
Debian DSA