CVE-2026-80978High· 7.0▾ TwilightA flaw was found in the Linux kernel, specifically within its IP tunnel devices. A local attacker could create a stack of user-controlled IP tunnel devices, causing the system to miscalculate the required memory for network packet headers.…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 4.1
none → medium
— → 4.1
none → medium
— → 7.8
none → high
Last analysed / modified upstream
7.8 → 4.1
high → medium
7.8 → 7
A flaw was found in the Linux kernel, specifically within its IP tunnel devices. A local attacker could create a stack of user-controlled IP tunnel devices, causing the system to miscalculate the required memory for network packet headers. This miscalculation can lead to unnecessary memory reallocations during packet transmission, which may result in performance degradation for network operations.
kernel: net: cap advertised IP tunnel headroom — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.
Affected:
No fix planned:
Out of support scope
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80948Medium· 5.5kernel: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() (CVE-2026-80948)
CVE-2026-80936Medium· 5.5kernel: wifi: mt76: mt7925: cancel mlo_pm_work on stop (CVE-2026-80936)
CVE-2026-80947High· 7.0kernel: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop (CVE-2026-80947)
CVE-2026-80980Medium· 5.5kernel: net/smc: stop killed, freed and out_of_sync sharing a byte (CVE-2026-80980)
CVE-2026-80981High· 7.0kernel: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() (CVE-2026-80981)
CVE-2026-80985High· 7.0kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry (CVE-2026-80985)