Bug 2532487 (CVE-2026-80978) - CVE-2026-80978 kernel: net: cap advertised IP tunnel headroom
Summary: CVE-2026-80978 kernel: net: cap advertised IP tunnel headroom
Keywords:
Status: NEW
Alias: CVE-2026-80978
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-11 23:26 UTC by OSIDB Bzimport
Modified: 2026-09-14 18:42 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-11 23:26:14 UTC
In the Linux kernel, the following vulnerability has been resolved:

net: cap advertised IP tunnel headroom

IP tunnel devices derive their advertised needed_headroom from lower
output devices. A stack of user-created devices can make the derived
value larger than the 16-bit skb header offsets can represent. Once IP
output reserves it, skb head expansion can wrap those offsets.

The runtime transmit path already caps a growing needed_headroom at 512.
Apply the same cap when tunnel configuration publishes needed_headroom
derived from a lower output device.

Capping the advertised value is safe: IP tunnel transmit still expands
the skb when a packet needs more headroom. A nonsensical stacked
configuration can therefore incur an extra reallocation, but it cannot
publish an unbounded reservation to upper layers.


Note You need to log in before you can comment on or make changes to this bug.