Bug 2532176 (CVE-2026-81000) - CVE-2026-81000 kernel: net: tun: bound receive headroom
Summary: CVE-2026-81000 kernel: net: tun: bound receive headroom
Keywords:
Status: NEW
Alias: CVE-2026-81000
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-11 21:07 UTC by OSIDB Bzimport
Modified: 2026-09-25 04:24 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:71016 0 None None None 2026-09-23 18:08:50 UTC
Red Hat Product Errata RHSA-2026:71213 0 None None None 2026-09-24 01:02:51 UTC
Red Hat Product Errata RHSA-2026:71232 0 None None None 2026-09-24 05:52:49 UTC
Red Hat Product Errata RHSA-2026:71233 0 None None None 2026-09-24 03:01:13 UTC
Red Hat Product Errata RHSA-2026:71565 0 None None None 2026-09-24 10:34:32 UTC
Red Hat Product Errata RHSA-2026:71569 0 None None None 2026-09-24 13:43:27 UTC
Red Hat Product Errata RHSA-2026:71592 0 None None None 2026-09-24 11:51:12 UTC
Red Hat Product Errata RHSA-2026:71594 0 None None None 2026-09-24 12:42:21 UTC
Red Hat Product Errata RHSA-2026:71599 0 None None None 2026-09-24 14:17:58 UTC
Red Hat Product Errata RHSA-2026:71601 0 None None None 2026-09-24 13:46:44 UTC
Red Hat Product Errata RHSA-2026:71606 0 None None None 2026-09-24 12:54:50 UTC
Red Hat Product Errata RHSA-2026:71631 0 None None None 2026-09-24 18:48:11 UTC
Red Hat Product Errata RHSA-2026:71657 0 None None None 2026-09-24 16:16:59 UTC
Red Hat Product Errata RHSA-2026:71687 0 None None None 2026-09-24 22:30:44 UTC

Description OSIDB Bzimport 2026-09-11 21:07:43 UTC
In the Linux kernel, the following vulnerability has been resolved:

net: tun: bound receive headroom

tun_get_user() uses tun->align both as skb headroom and when choosing how
much packet data to keep linear. OVS can propagate an oversized headroom
request from another port to TUN or TAP.

When align is larger than the usable space in a one-page skb head,
SKB_MAX_HEAD(align) underflows and the result becomes negative when stored
in good_linear. That value later wraps when assigned to the size_t linear
variable, and tun_alloc_skb() can place skb->data outside the allocated
head.

Bound the headroom stored by TUN to the one-page skb-head budget and the
largest non-sentinel 16-bit skb header offset. Leave one linear byte for
raw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN.

Also pull the raw-TUN protocol byte and the TAP Ethernet header before
accessing them, so these checks remain safe for nonlinear skbs supplied by
other allocation paths.

Comment 4 Akiyoshi Kurita 2026-09-18 15:16:40 UTC
A public local privilege escalation PoC for CVE-2026-81000 (TUNderflow) has been published.

PoC:
https://github.com/manizada/TUNderflow

oss-security disclosure:
https://seclists.org/oss-sec/2026/q3/822

Upstream fix:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=447c9303942c439a117d9b76ce6d6e2116b38ee7

Stable backports:
https://git.kernel.org/stable/c/379d85c7f25f3e05a428225e6b8a65613c6e9b9d
https://git.kernel.org/stable/c/e098d9cc8859614a7f7baebc96e32a5a16b18ed2
https://git.kernel.org/stable/c/0ada54ea63e48b9c1608e917ccb7dfadbe86db28
https://git.kernel.org/stable/c/447c9303942c439a117d9b76ce6d6e2116b38ee7

The published PoC demonstrates local user-to-root privilege escalation.

Possible mitigation on systems that do not require TUN/TAP:

echo "install tun /bin/true" > /etc/modprobe.d/disable-tun.conf

Please re-evaluate the impact on supported RHEL kernels based on the published LPE PoC and upstream/stable fixes.

Comment 9 Jon Orris 2026-09-23 18:08:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:71016 https://access.redhat.com/errata/RHSA-2026:71016

Comment 10 Jon Orris 2026-09-24 01:02:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:71213 https://access.redhat.com/errata/RHSA-2026:71213

Comment 11 Jon Orris 2026-09-24 03:01:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:71233 https://access.redhat.com/errata/RHSA-2026:71233

Comment 12 Jon Orris 2026-09-24 05:52:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:71232 https://access.redhat.com/errata/RHSA-2026:71232

Comment 13 Jon Orris 2026-09-24 10:34:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:71565 https://access.redhat.com/errata/RHSA-2026:71565

Comment 14 Jon Orris 2026-09-24 11:51:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:71592 https://access.redhat.com/errata/RHSA-2026:71592

Comment 15 Jon Orris 2026-09-24 12:42:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:71594 https://access.redhat.com/errata/RHSA-2026:71594

Comment 16 Jon Orris 2026-09-24 12:54:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:71606 https://access.redhat.com/errata/RHSA-2026:71606

Comment 17 Jon Orris 2026-09-24 13:43:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:71569 https://access.redhat.com/errata/RHSA-2026:71569

Comment 18 Jon Orris 2026-09-24 13:46:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:71601 https://access.redhat.com/errata/RHSA-2026:71601

Comment 19 Jon Orris 2026-09-24 14:17:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:71599 https://access.redhat.com/errata/RHSA-2026:71599

Comment 20 Jon Orris 2026-09-24 16:16:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:71657 https://access.redhat.com/errata/RHSA-2026:71657

Comment 21 Jon Orris 2026-09-24 18:48:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:71631 https://access.redhat.com/errata/RHSA-2026:71631

Comment 22 Jon Orris 2026-09-24 22:30:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:71687 https://access.redhat.com/errata/RHSA-2026:71687


Note You need to log in before you can comment on or make changes to this bug.