Bug 2532176 (CVE-2026-81000)

Summary: CVE-2026-81000 kernel: net: tun: bound receive headroom
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akhatavk, akito5623, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Linux kernel's TUN/TAP driver. An integer underflow vulnerability exists in the tun_get_user() function when processing oversized headroom requests. This can occur if Open vSwitch (OVS) propagates an excessively large headroom request to the TUN or TAP device. Successful exploitation could lead to memory corruption, where network packet data is written outside its intended buffer, potentially causing a denial of service or other system instability.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-11 21:07:43 UTC
In the Linux kernel, the following vulnerability has been resolved:

net: tun: bound receive headroom

tun_get_user() uses tun->align both as skb headroom and when choosing how
much packet data to keep linear. OVS can propagate an oversized headroom
request from another port to TUN or TAP.

When align is larger than the usable space in a one-page skb head,
SKB_MAX_HEAD(align) underflows and the result becomes negative when stored
in good_linear. That value later wraps when assigned to the size_t linear
variable, and tun_alloc_skb() can place skb->data outside the allocated
head.

Bound the headroom stored by TUN to the one-page skb-head budget and the
largest non-sentinel 16-bit skb header offset. Leave one linear byte for
raw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN.

Also pull the raw-TUN protocol byte and the TAP Ethernet header before
accessing them, so these checks remain safe for nonlinear skbs supplied by
other allocation paths.

Comment 4 Akiyoshi Kurita 2026-09-18 15:16:40 UTC
A public local privilege escalation PoC for CVE-2026-81000 (TUNderflow) has been published.

PoC:
https://github.com/manizada/TUNderflow

oss-security disclosure:
https://seclists.org/oss-sec/2026/q3/822

Upstream fix:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=447c9303942c439a117d9b76ce6d6e2116b38ee7

Stable backports:
https://git.kernel.org/stable/c/379d85c7f25f3e05a428225e6b8a65613c6e9b9d
https://git.kernel.org/stable/c/e098d9cc8859614a7f7baebc96e32a5a16b18ed2
https://git.kernel.org/stable/c/0ada54ea63e48b9c1608e917ccb7dfadbe86db28
https://git.kernel.org/stable/c/447c9303942c439a117d9b76ce6d6e2116b38ee7

The published PoC demonstrates local user-to-root privilege escalation.

Possible mitigation on systems that do not require TUN/TAP:

echo "install tun /bin/true" > /etc/modprobe.d/disable-tun.conf

Please re-evaluate the impact on supported RHEL kernels based on the published LPE PoC and upstream/stable fixes.

Comment 9 Jon Orris 2026-09-23 18:08:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:71016 https://access.redhat.com/errata/RHSA-2026:71016

Comment 10 Jon Orris 2026-09-24 01:02:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:71213 https://access.redhat.com/errata/RHSA-2026:71213

Comment 11 Jon Orris 2026-09-24 03:01:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:71233 https://access.redhat.com/errata/RHSA-2026:71233

Comment 12 Jon Orris 2026-09-24 05:52:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:71232 https://access.redhat.com/errata/RHSA-2026:71232

Comment 13 Jon Orris 2026-09-24 10:34:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:71565 https://access.redhat.com/errata/RHSA-2026:71565

Comment 14 Jon Orris 2026-09-24 11:51:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:71592 https://access.redhat.com/errata/RHSA-2026:71592

Comment 15 Jon Orris 2026-09-24 12:42:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:71594 https://access.redhat.com/errata/RHSA-2026:71594

Comment 16 Jon Orris 2026-09-24 12:54:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:71606 https://access.redhat.com/errata/RHSA-2026:71606

Comment 17 Jon Orris 2026-09-24 13:43:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:71569 https://access.redhat.com/errata/RHSA-2026:71569

Comment 18 Jon Orris 2026-09-24 13:46:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:71601 https://access.redhat.com/errata/RHSA-2026:71601

Comment 19 Jon Orris 2026-09-24 14:17:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:71599 https://access.redhat.com/errata/RHSA-2026:71599

Comment 20 Jon Orris 2026-09-24 16:16:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:71657 https://access.redhat.com/errata/RHSA-2026:71657

Comment 21 Jon Orris 2026-09-24 18:48:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:71631 https://access.redhat.com/errata/RHSA-2026:71631

Comment 22 Jon Orris 2026-09-24 22:30:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:71687 https://access.redhat.com/errata/RHSA-2026:71687

Comment 23 Jon Orris 2026-09-30 07:46:30 UTC
This issue has been addressed in the following products:

  NVIDIA for RHEL 10

Via RHSA-2026:73788 https://access.redhat.com/errata/RHSA-2026:73788

Comment 24 Jon Orris 2026-10-06 12:01:11 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.22

Via RHSA-2026:74428 https://access.redhat.com/errata/RHSA-2026:74428

Comment 25 Jon Orris 2026-10-06 12:32:50 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.21

Via RHSA-2026:74379 https://access.redhat.com/errata/RHSA-2026:74379

Comment 26 Jon Orris 2026-10-06 18:56:32 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.20

Via RHSA-2026:74377 https://access.redhat.com/errata/RHSA-2026:74377

Comment 27 Jon Orris 2026-10-07 10:24:43 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.19

Via RHSA-2026:74433 https://access.redhat.com/errata/RHSA-2026:74433