{"id":"CVE-2026-81000","title":"kernel: net: tun: bound receive headroom (CVE-2026-81000)","summary":"A flaw was found in the Linux kernel's TUN/TAP driver. An integer underflow vulnerability exists in the tun_get_user() function when processing oversized headroom requests. This can occur if Open vSwitch (OVS) propagates an excessively lar…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-787","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 7","enterprise_linux 9","enterprise_linux_for_nvidia 26","openshift_container_platform 4","enterprise_linux_baseos_v_8","enterprise_linux_crb_v_8","enterprise_linux_nfv_v_8","enterprise_linux_rt_v_8"],"patched":["enterprise_linux_baseos_v_8","enterprise_linux_crb_v_8","enterprise_linux_nfv_v_8","enterprise_linux_rt_v_8"],"published":"2026-09-11","updated":"2026-09-24","sourceUpdated":"2026-09-24T02:24:24+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81000.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81000.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-81000"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532176"},{"url":"https://access.redhat.com/security/vulnerabilities/RHSB-2026-011"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81000"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81000"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-81000.mbox"},{"url":"https://access.redhat.com/errata/RHSA-2026:71213"},{"url":"https://access.redhat.com/errata/RHSA-2026:71016"},{"url":"https://git.kernel.org/stable/c/ad715e713610d2d5473c3a6498c825ccecf26491"},{"url":"https://git.kernel.org/stable/c/708e87937de93f445225c134a2e20519f9b4ce60"},{"url":"https://git.kernel.org/stable/c/18ef24cdb2eba32e38f1d27f2d02b7b4212e8f76"},{"url":"https://git.kernel.org/stable/c/010eee265d6bd8769b6a523d2a0693d9b3f5df43"},{"url":"https://git.kernel.org/stable/c/379d85c7f25f3e05a428225e6b8a65613c6e9b9d"},{"url":"https://git.kernel.org/stable/c/e098d9cc8859614a7f7baebc96e32a5a16b18ed2"},{"url":"https://git.kernel.org/stable/c/0ada54ea63e48b9c1608e917ccb7dfadbe86db28"},{"url":"https://git.kernel.org/stable/c/447c9303942c439a117d9b76ce6d6e2116b38ee7"}],"tags":["csaf","vex","red-hat","exploit-available","cve.org"],"epss":0.00164,"epssPercentile":0.06025,"exploits":{"github":2,"githubRepos":["https://github.com/0xBlackash/CVE-2026-81000","https://github.com/HORKimhab/CVE-2026-81000"],"checkedAt":"2026-09-24T07:40:06.455Z"},"exploitAvailable":true,"ingestedAt":"2026-09-14T15:23:07.454Z","slug":"CVE-2026-81000","body":"## Overview\n\nA flaw was found in the Linux kernel's TUN/TAP driver. An integer underflow vulnerability exists in the tun_get_user() function when processing oversized headroom requests. This can occur if Open vSwitch (OVS) propagates an excessively large headroom request to the TUN or TAP device. Successful exploitation could lead to memory corruption, where network packet data is written outside its intended buffer, potentially causing a denial of service or other system instability.\n\n## Vendor advisories\n\n- **RHSA-2026:71213** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71213)\n- **RHSA-2026:71016** · Red Hat · fixed in: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71016)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux for NVIDIA 26, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux for NVIDIA 26, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81000.json)\n\n**kernel: net: tun: bound receive headroom** — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-24.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux for NVIDIA 26\n- Red Hat OpenShift Container Platform 4\n\nFixed:\n\n- Red Hat Enterprise Linux BaseOS (v. 8)\n- Red Hat Enterprise Linux CRB (v. 8)\n- Red Hat Enterprise Linux NFV (v. 8)\n- Red Hat Enterprise Linux RT (v. 8)\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux for NVIDIA 26\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nThe system must be rebooted for this update to take effect.\n\nRed Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture.\n\nBecause of this proactive approach, a patch may be associa… https://access.redhat.com/errata/RHSA-2026:71213\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nThe system must be rebooted for this update to take effect.\n\nRed Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture.\n\nBecause of this proactive approach, a patch may be associa… https://access.redhat.com/errata/RHSA-2026:71016\n\nWorkarounds / mitigations:\n\n- See the security bulletin for a detailed mitigation procedure.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":208488,"id":"CVE-2026-81000","ts":1790005719113,"field":"cvss","old":"7","new":"7.8"},{"seq":208063,"id":"CVE-2026-81000","ts":1789922701014,"field":"exploit_available","old":"false","new":"true"},{"seq":208062,"id":"CVE-2026-81000","ts":1789922701014,"field":"cvss","old":"7.8","new":"7"},{"seq":183809,"id":"CVE-2026-81000","ts":1789356677483,"field":"cvss","old":"7.8","new":"6.4"},{"seq":183808,"id":"CVE-2026-81000","ts":1789356677483,"field":"severity","old":"high","new":"medium"},{"seq":153190,"id":"CVE-2026-81000","ts":1789285349479,"field":"cvss","old":null,"new":"7.8"},{"seq":153189,"id":"CVE-2026-81000","ts":1789285349479,"field":"severity","old":"none","new":"high"},{"seq":147658,"id":"CVE-2026-81000","ts":1789270211772,"field":"cvss","old":null,"new":"6.4"},{"seq":147657,"id":"CVE-2026-81000","ts":1789270211772,"field":"severity","old":"none","new":"medium"},{"seq":109414,"id":"CVE-2026-81000","ts":1789183731821,"field":"cvss","old":null,"new":"6.4"},{"seq":109413,"id":"CVE-2026-81000","ts":1789183731821,"field":"severity","old":"none","new":"medium"}]}