Description
In the Linux kernel, the following vulnerability has been resolved:

ip6_gre: fix hardware header length for NBMA tunnels

ip6gre_tnl_link_config_route() accumulates the lower device's hardware
header length into dev->hard_header_len whenever header_ops is set. This
is incorrect for both users of header_ops.

ip6gretap and ip6erspan have a fixed Ethernet hardware header length.
For an NBMA ip6gre tunnel, ip6gre_header() creates only the GRE header,
the optional FOU or GUE header, and the outer IPv6 header. The lower
device header is headroom needed later, not part of the tunnel device's
hardware header.

Keep the lower device header in needed_headroom. Set hard_header_len to
the tunnel header length only for ARPHRD_IP6GRE devices with header_ops,
and leave the fixed Ethernet header length unchanged for tap and erspan
devices.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Incorrect hardware header length calculation for NBMA GRE tunnels
Action: Update Kernel
AI Analysis

Impact

The Linux kernel bug causes the hard_header_len of NBMA GRE tunnels to incorrectly include the lower device’s hardware header length when header_ops is enabled. This miscalculation can lead to inaccurate header length values for ARPHRD_IP6GRE devices that use header_ops, while tap and erspan devices retain their fixed Ethernet header header calculation.

Affected Systems

Linux kernel versions that do not505b6d296c486ef7d1274f279d4c43a172f63224) are affected. Distributions shipping kernel releases prior to that commit, as well as custom kernel builds that enable header_ops for ARPHRD_IP6GRE devices without the patch, remain vulnerable.

Risk and Exploitability

The CVSS score is 7.8, indicating high severity, while the EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low exploitation probability. The likely attack vector is traffic to a vulnerable interface, which could trigger the incorrect header calculation. No further exploitation method is documented beyond the incorrect header length handling.

Generated by OpenCVE AI on September 15, 2026 at 21:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the hard_header_len fix for NBMA IP6GRE tunnels.
  • If an update cannot be applied immediately, restrict GRE traffic on interfaces that use affected NBMA tunnels by configuring firewall rules or disabling the tunnels.
  • Continue monitoring kernel logs and network traffic for GRE packet anomalies, and adjust firewall policies to mitigate potential misrouting until the patch is fully deployed.

Generated by OpenCVE AI on September 15, 2026 at 21:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Tue, 15 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-129

Mon, 14 Sep 2026 12:30:00 +0000


Mon, 14 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-129

Sun, 13 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-129

Sun, 13 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-129

Sun, 13 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-124
CWE-129

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-124
CWE-129

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ip6_gre: fix hardware header length for NBMA tunnels ip6gre_tnl_link_config_route() accumulates the lower device's hardware header length into dev->hard_header_len whenever header_ops is set. This is incorrect for both users of header_ops. ip6gretap and ip6erspan have a fixed Ethernet hardware header length. For an NBMA ip6gre tunnel, ip6gre_header() creates only the GRE header, the optional FOU or GUE header, and the outer IPv6 header. The lower device header is headroom needed later, not part of the tunnel device's hardware header. Keep the lower device header in needed_headroom. Set hard_header_len to the tunnel header length only for ARPHRD_IP6GRE devices with header_ops, and leave the fixed Ethernet header length unchanged for tap and erspan devices.
Title ip6_gre: fix hardware header length for NBMA tunnels
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:02.225Z

Reserved: 2026-09-11T19:38:34.725Z

Link: CVE-2026-89562

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:40.063

Modified: 2026-09-14T13:19:11.270

Link: CVE-2026-89562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses
  • CWE-20

    Improper Input Validation