{"id":"CVE-2026-80978","title":"kernel: net: cap advertised IP tunnel headroom (CVE-2026-80978)","summary":"A flaw was found in the Linux kernel, specifically within its IP tunnel devices. A local attacker could create a stack of user-controlled IP tunnel devices, causing the system to miscalculate the required memory for network packet headers.…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-190","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 6","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T18:58:28+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80978.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80978.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80978"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532487"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80978"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80978"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80978.mbox"},{"url":"https://git.kernel.org/stable/c/fb889a619723032140f5d983a3a34d25a5a2bed4"},{"url":"https://git.kernel.org/stable/c/b160422f8103574425e2834130e169d84c94fa1d"},{"url":"https://git.kernel.org/stable/c/d36e75f5669140b66515ad3a176ca6337bd80a5e"},{"url":"https://git.kernel.org/stable/c/84783961cb8bdb36b4f41a02ce43aafc6d52b176"},{"url":"https://git.kernel.org/stable/c/bc4e05ae66c9797a0972ac44326e69c5305e0020"},{"url":"https://git.kernel.org/stable/c/af0ee8f04bea22cdb331fa3509e17f81b48938ad"},{"url":"https://git.kernel.org/stable/c/9144f2c53a04465a6878172b523f640313c5559e"},{"url":"https://git.kernel.org/stable/c/6b222adeb9340306e2ff97127c76117abb9b3df8"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00129,"epssPercentile":0.02909,"scores":{"vendor":7,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.454Z","slug":"CVE-2026-80978","body":"## Overview\n\nA flaw was found in the Linux kernel, specifically within its IP tunnel devices. A local attacker could create a stack of user-controlled IP tunnel devices, causing the system to miscalculate the required memory for network packet headers. This miscalculation can lead to unnecessary memory reallocations during packet transmission, which may result in performance degradation for network operations.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80978.json)\n\n**kernel: net: cap advertised IP tunnel headroom** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nOut of support scope","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204182,"id":"CVE-2026-80978","ts":1789490237324,"field":"cvss","old":"7.8","new":"7"},{"seq":183598,"id":"CVE-2026-80978","ts":1789356676044,"field":"cvss","old":"7.8","new":"4.1"},{"seq":183597,"id":"CVE-2026-80978","ts":1789356676044,"field":"severity","old":"high","new":"medium"},{"seq":153160,"id":"CVE-2026-80978","ts":1789285349348,"field":"cvss","old":null,"new":"7.8"},{"seq":153159,"id":"CVE-2026-80978","ts":1789285349348,"field":"severity","old":"none","new":"high"},{"seq":147135,"id":"CVE-2026-80978","ts":1789270196096,"field":"cvss","old":null,"new":"4.1"},{"seq":147134,"id":"CVE-2026-80978","ts":1789270196096,"field":"severity","old":"none","new":"medium"},{"seq":108890,"id":"CVE-2026-80978","ts":1789183729423,"field":"cvss","old":null,"new":"4.1"},{"seq":108889,"id":"CVE-2026-80978","ts":1789183729423,"field":"severity","old":"none","new":"medium"}]}