Description
In the Linux kernel, the following vulnerability has been resolved:

net: tun: bound receive headroom

tun_get_user() uses tun->align both as skb headroom and when choosing how
much packet data to keep linear. OVS can propagate an oversized headroom
request from another port to TUN or TAP.

When align is larger than the usable space in a one-page skb head,
SKB_MAX_HEAD(align) underflows and the result becomes negative when stored
in good_linear. That value later wraps when assigned to the size_t linear
variable, and tun_alloc_skb() can place skb->data outside the allocated
head.

Bound the headroom stored by TUN to the one-page skb-head budget and the
largest non-sentinel 16-bit skb header offset. Leave one linear byte for
raw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN.

Also pull the raw-TUN protocol byte and the TAP Ethernet header before
accessing them, so these checks remain safe for nonlinear skbs supplied by
other allocation paths.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption (CWE‑787) potentially leading to privilege escalation or service disruption
Action: Patch immediately
AI Analysis

Impact

In the Linux kernel, the tun_get_user function uses tun->align both as skb headroom and to determine how much packet data to keep linear. When an oversized headroom request is propagated, the calculation of SKB_MAX_HEAD(align) can underflow, producing a negative good_linear value. That value, when cast to an unsigned size_t, causes tun_alloc_skb() to place skb->data outside the allocated head area, leading to kernel memory corruption that can be exploited for arbitrary code execution or a system crash.

Affected Systems

The flaw resides in the net kernel. Any kernel build that contains the unpatched tun code is affected, regardless of distribution. The CPE string cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* indicates that all Linux kernel releases prior to the patch are vulnerable. This includes common distributions such as Ubuntu, Debian, Red Hat, SUSE, and others that ship vanilla kernel releases.

Risk and Exploitability

The CVSS score of 7.8 classifies the vulnerability as high severity. The EPSS score of <1 % suggests a low probability of active exploitation, and the flaw is not listed in the CISA KEV catalog, meaning no publicly known exploits exist yet. An attacker would typically need to influence a tun interface—often through a privileged or compromised network service or a tool like Open vSwitch—to trigger the underflow and cause kernel memory corruption. Despite the low exploitation likelihood, the kernel‑level impact warrants immediate remediation.

Generated by OpenCVE AI on September 21, 2026 at 02:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a build that includes the patch for the tun/TAP headroom bug.
  • If an immediate kernel upgrade is not possible, restrict access to tun/TAP interfaces: map them to trusted users only and enforce firewall rules to block untrusted traffic; configure Open vSwitch to prevent oversized headroom propagation.
  • Apply distribution‑provided security patches and updates regularly to reduce the risk of related vulnerabilities.

Generated by OpenCVE AI on September 21, 2026 at 02:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the result becomes negative when stored in good_linear. That value later wraps when assigned to the size_t linear variable, and tun_alloc_skb() can place skb->data outside the allocated head. Bound the headroom stored by TUN to the one-page skb-head budget and the largest non-sentinel 16-bit skb header offset. Leave one linear byte for raw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN. Also pull the raw-TUN protocol byte and the TAP Ethernet header before accessing them, so these checks remain safe for nonlinear skbs supplied by other allocation paths.
Title net: tun: bound receive headroom
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:35.300Z

Reserved: 2026-08-26T14:34:25.812Z

Link: CVE-2026-81000

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:07.710

Modified: 2026-09-14T13:18:54.210

Link: CVE-2026-81000

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:54Z

Links: CVE-2026-81000 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:45:08Z

Weaknesses