CVE-2026-81000High· 7.8▾ MidnightPoC availableA flaw was found in the Linux kernel's TUN/TAP driver. An integer underflow vulnerability exists in the tun_get_user() function when processing oversized headroom requests. This can occur if Open vSwitch (OVS) propagates an excessively lar…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 42.9 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 6.4
none → medium
— → 6.4
none → medium
— → 7.8
none → high
7.8 → 6.4
high → medium
2 GitHub repos
7.8 → 7
Last analysed / modified upstream
7 → 7.8
A flaw was found in the Linux kernel's TUN/TAP driver. An integer underflow vulnerability exists in the tun_get_user() function when processing oversized headroom requests. This can occur if Open vSwitch (OVS) propagates an excessively large headroom request to the TUN or TAP device. Successful exploitation could lead to memory corruption, where network packet data is written outside its intended buffer, potentially causing a denial of service or other system instability.
kernel: net: tun: bound receive headroom — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-21.
Affected:
No fix planned:
Not affected:
Affected
Workarounds / mitigations:
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80986High· 7.0kernel: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages (CVE-2026-80986)
CVE-2026-80944High· 7.0kernel: wifi: mwifiex: Detach sync cmd buffer on interrupted wait (CVE-2026-80944)
CVE-2026-80951High· 7.0kernel: i3c: master: svc: bound IBI payload to the requested max_payload_len (CVE-2026-80951)
CVE-2026-81002High· 7.0kernel: xdp: fix zero-copy frame layout (CVE-2026-81002)
CVE-2026-89438Medium· 5.5kernel: platform/x86: ISST: Validate logical CPU id and clos id (CVE-2026-89438)
CVE-2026-89482High· 7.0kernel: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone (CVE-2026-89482)