Bug 2532176 (CVE-2026-81000)
| Summary: | CVE-2026-81000 kernel: net: tun: bound receive headroom | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | akhatavk, akito5623, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's TUN/TAP driver. An integer underflow vulnerability exists in the tun_get_user() function when processing oversized headroom requests. This can occur if Open vSwitch (OVS) propagates an excessively large headroom request to the TUN or TAP device. Successful exploitation could lead to memory corruption, where network packet data is written outside its intended buffer, potentially causing a denial of service or other system instability.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-11 21:07:43 UTC
Upstream advisory: https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-81000.mbox A public local privilege escalation PoC for CVE-2026-81000 (TUNderflow) has been published. PoC: https://github.com/manizada/TUNderflow oss-security disclosure: https://seclists.org/oss-sec/2026/q3/822 Upstream fix: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=447c9303942c439a117d9b76ce6d6e2116b38ee7 Stable backports: https://git.kernel.org/stable/c/379d85c7f25f3e05a428225e6b8a65613c6e9b9d https://git.kernel.org/stable/c/e098d9cc8859614a7f7baebc96e32a5a16b18ed2 https://git.kernel.org/stable/c/0ada54ea63e48b9c1608e917ccb7dfadbe86db28 https://git.kernel.org/stable/c/447c9303942c439a117d9b76ce6d6e2116b38ee7 The published PoC demonstrates local user-to-root privilege escalation. Possible mitigation on systems that do not require TUN/TAP: echo "install tun /bin/true" > /etc/modprobe.d/disable-tun.conf Please re-evaluate the impact on supported RHEL kernels based on the published LPE PoC and upstream/stable fixes. This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:71016 https://access.redhat.com/errata/RHSA-2026:71016 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:71213 https://access.redhat.com/errata/RHSA-2026:71213 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:71233 https://access.redhat.com/errata/RHSA-2026:71233 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:71232 https://access.redhat.com/errata/RHSA-2026:71232 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:71565 https://access.redhat.com/errata/RHSA-2026:71565 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:71592 https://access.redhat.com/errata/RHSA-2026:71592 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:71594 https://access.redhat.com/errata/RHSA-2026:71594 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:71606 https://access.redhat.com/errata/RHSA-2026:71606 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:71569 https://access.redhat.com/errata/RHSA-2026:71569 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:71601 https://access.redhat.com/errata/RHSA-2026:71601 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:71599 https://access.redhat.com/errata/RHSA-2026:71599 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:71657 https://access.redhat.com/errata/RHSA-2026:71657 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:71631 https://access.redhat.com/errata/RHSA-2026:71631 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:71687 https://access.redhat.com/errata/RHSA-2026:71687 This issue has been addressed in the following products: NVIDIA for RHEL 10 Via RHSA-2026:73788 https://access.redhat.com/errata/RHSA-2026:73788 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.22 Via RHSA-2026:74428 https://access.redhat.com/errata/RHSA-2026:74428 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.21 Via RHSA-2026:74379 https://access.redhat.com/errata/RHSA-2026:74379 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.20 Via RHSA-2026:74377 https://access.redhat.com/errata/RHSA-2026:74377 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:74433 https://access.redhat.com/errata/RHSA-2026:74433 |