---
id: CVE-2026-81000
title: 'kernel: net: tun: bound receive headroom (CVE-2026-81000)'
summary: >-
  A flaw was found in the Linux kernel's TUN/TAP driver. An integer underflow
  vulnerability exists in the tun_get_user() function when processing oversized
  headroom requests. This can occur if Open vSwitch (OVS) propagates an
  excessively lar…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-787
vendor: Red Hat
product: Red Hat Enterprise Linux BaseOS E4S (v.9.4)
affected:
  - enterprise_linux 10
  - enterprise_linux 9
  - enterprise_linux_for_nvidia 26
  - openshift_container_platform 4
  - enterprise_linux_server_v_7_els
  - enterprise_linux_for_real_time_v_7_els
  - enterprise_linux_server_optional_v_7_els
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_eus_v_10_0
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_aus_v_8_4
  - enterprise_linux_baseos_eus_extension_v_8_4
  - enterprise_linux_baseos_aus_v_8_6
  - enterprise_linux_baseos_eus_extension_v_8_6
  - enterprise_linux_baseos_e4s_v_8_8
  - enterprise_linux_baseos_tus_v_8_8
  - enterprise_linux_baseos_e4s_v_9_2
  - enterprise_linux_baseos_e4s_v_9_4
  - enterprise_linux_baseos_eus_v_9_6
  - enterprise_linux_baseos_v_9
  - enterprise_linux_codeready_linux_builder_eus_v_10_0
  - enterprise_linux_codeready_linux_builder_v_10
  - enterprise_linux_crb_v_8
  - codeready_linux_builder_eus_v_9_6
  - enterprise_linux_codeready_linux_builder_v_9
  - enterprise_linux_real_time_for_nfv_eus_v_10_0
  - enterprise_linux_real_time_for_nfv_v_10
  - enterprise_linux_nfv_v_8
  - enterprise_linux_real_time_for_nfv_e4s_v_9_2
  - enterprise_linux_real_time_for_nfv_e4s_v_9_4
  - enterprise_linux_real_time_for_nfv_eus_v_9_6
  - enterprise_linux_real_time_for_nfv_v_9
  - enterprise_linux_real_time_eus_v_10_0
  - enterprise_linux_real_time_v_10
patched:
  - enterprise_linux_server_v_7_els
  - enterprise_linux_for_real_time_v_7_els
  - enterprise_linux_server_optional_v_7_els
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_eus_v_10_0
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_aus_v_8_4
  - enterprise_linux_baseos_eus_extension_v_8_4
  - enterprise_linux_baseos_aus_v_8_6
  - enterprise_linux_baseos_eus_extension_v_8_6
  - enterprise_linux_baseos_e4s_v_8_8
  - enterprise_linux_baseos_tus_v_8_8
  - enterprise_linux_baseos_e4s_v_9_2
  - enterprise_linux_baseos_e4s_v_9_4
  - enterprise_linux_baseos_eus_v_9_6
  - enterprise_linux_baseos_v_9
  - enterprise_linux_codeready_linux_builder_eus_v_10_0
  - enterprise_linux_codeready_linux_builder_v_10
  - enterprise_linux_crb_v_8
  - codeready_linux_builder_eus_v_9_6
  - enterprise_linux_codeready_linux_builder_v_9
  - enterprise_linux_real_time_for_nfv_eus_v_10_0
  - enterprise_linux_real_time_for_nfv_v_10
  - enterprise_linux_nfv_v_8
  - enterprise_linux_real_time_for_nfv_e4s_v_9_2
  - enterprise_linux_real_time_for_nfv_e4s_v_9_4
  - enterprise_linux_real_time_for_nfv_eus_v_9_6
  - enterprise_linux_real_time_for_nfv_v_9
  - enterprise_linux_real_time_eus_v_10_0
  - enterprise_linux_real_time_v_10
  - enterprise_linux_rt_v_8
  - enterprise_linux_real_time_e4s_v_9_2
  - enterprise_linux_real_time_e4s_v_9_4
  - enterprise_linux_real_time_eus_v_9_6
published: '2026-09-11'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T04:49:22+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81000.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81000.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-81000'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532176'
  - url: 'https://access.redhat.com/security/vulnerabilities/RHSB-2026-011'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-81000'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81000'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-81000.mbox
  - url: 'https://access.redhat.com/errata/RHSA-2026:71687'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71657'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71599'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71233'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71601'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71569'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71631'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71232'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71213'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71565'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71592'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71594'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71016'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71606'
  - url: 'https://git.kernel.org/stable/c/ad715e713610d2d5473c3a6498c825ccecf26491'
  - url: 'https://git.kernel.org/stable/c/708e87937de93f445225c134a2e20519f9b4ce60'
  - url: 'https://git.kernel.org/stable/c/18ef24cdb2eba32e38f1d27f2d02b7b4212e8f76'
  - url: 'https://git.kernel.org/stable/c/010eee265d6bd8769b6a523d2a0693d9b3f5df43'
  - url: 'https://git.kernel.org/stable/c/379d85c7f25f3e05a428225e6b8a65613c6e9b9d'
  - url: 'https://git.kernel.org/stable/c/e098d9cc8859614a7f7baebc96e32a5a16b18ed2'
  - url: 'https://git.kernel.org/stable/c/0ada54ea63e48b9c1608e917ccb7dfadbe86db28'
  - url: 'https://git.kernel.org/stable/c/447c9303942c439a117d9b76ce6d6e2116b38ee7'
tags:
  - csaf
  - vex
  - red-hat
  - exploit-available
  - cve.org
epss: 0.00357
epssPercentile: 0.26773
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/0xBlackash/CVE-2026-81000'
    - 'https://github.com/HORKimhab/CVE-2026-81000'
  checkedAt: '2026-09-26T09:06:01.692Z'
exploitAvailable: true
ingestedAt: '2026-09-14T15:23:07.454Z'
---

## Overview

A flaw was found in the Linux kernel's TUN/TAP driver. An integer underflow vulnerability exists in the tun_get_user() function when processing oversized headroom requests. This can occur if Open vSwitch (OVS) propagates an excessively large headroom request to the TUN or TAP device. Successful exploitation could lead to memory corruption, where network packet data is written outside its intended buffer, potentially causing a denial of service or other system instability.

## Vendor advisories

- **RHSA-2026:71687** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71687)
- **RHSA-2026:71657** · Red Hat · fixed in: Red Hat Enterprise Linux for Real Time (v. 7 ELS) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71657)
- **RHSA-2026:71599** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0), Red Hat Enterprise Linux Real Time for NFV EUS (v. 10.0), Red Hat Enterprise Linux Real Time EUS (v. 10.0) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71599)
- **RHSA-2026:71233** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10), Red Hat Enterprise Linux Real Time for NFV (v. 10), Red Hat Enterprise Linux Real Time (v. 10) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71233)
- **RHSA-2026:71601** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux BaseOS E4S (v.9.2) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71601)
- **RHSA-2026:71569** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4), Red Hat Enterprise Linux BaseOS E4S (v.9.4), Red Hat Enterprise Linux Real Time for NFV E4S (v.9.4), Red Hat Enterprise Linux Real Time E4S (v.9.4) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71569)
- **RHSA-2026:71631** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat Enterprise Linux BaseOS EUS (v.9.6), Red Hat CodeReady Linux Builder EUS (v.9.6), Red Hat Enterprise Linux Real Time for NFV EUS (v.9.6), Red Hat Enterprise Linux Real Time EUS (v.9.6) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71631)
- **RHSA-2026:71232** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9), Red Hat Enterprise Linux Real Time (v. 9) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71232)
- **RHSA-2026:71213** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71213)
- **RHSA-2026:71565** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS AUS (v.8.4), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71565)
- **RHSA-2026:71592** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS AUS (v.8.6), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71592)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux for NVIDIA 26, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux for NVIDIA 26, Red Hat OpenShift Container Platform 4 · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81000.json)
- **RHSA-2026:71016** · Red Hat · fixed in: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71016)

**kernel: net: tun: bound receive headroom** — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-25.

Affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux for NVIDIA 26
- Red Hat OpenShift Container Platform 4

Fixed:

- Red Hat Enterprise Linux Server (v. 7 ELS)
- Red Hat Enterprise Linux for Real Time (v. 7 ELS)
- Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- Red Hat Enterprise Linux BaseOS (v. 10)
- Red Hat Enterprise Linux BaseOS (v. 8)
- Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- Red Hat Enterprise Linux BaseOS AUS (v.8.6)
- Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
- Red Hat Enterprise Linux BaseOS E4S (v.8.8)
- Red Hat Enterprise Linux BaseOS TUS (v.8.8)
- Red Hat Enterprise Linux BaseOS E4S (v.9.2)
- Red Hat Enterprise Linux BaseOS E4S (v.9.4)
- Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- Red Hat Enterprise Linux BaseOS (v. 9)
- Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
- Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- Red Hat Enterprise Linux CRB (v. 8)
- Red Hat CodeReady Linux Builder EUS (v.9.6)
- Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- Red Hat Enterprise Linux Real Time for NFV EUS (v. 10.0)
- Red Hat Enterprise Linux Real Time for NFV (v. 10)
- Red Hat Enterprise Linux NFV (v. 8)
- Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- Red Hat Enterprise Linux Real Time for NFV E4S (v.9.4)
- Red Hat Enterprise Linux Real Time for NFV EUS (v.9.6)
- Red Hat Enterprise Linux Real Time for NFV (v. 9)
- Red Hat Enterprise Linux Real Time EUS (v. 10.0)
- Red Hat Enterprise Linux Real Time (v. 10)
- Red Hat Enterprise Linux RT (v. 8)
- Red Hat Enterprise Linux Real Time E4S (v.9.2)
- Red Hat Enterprise Linux Real Time E4S (v.9.4)
- Red Hat Enterprise Linux Real Time EUS (v.9.6)

No fix planned:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux for NVIDIA 26
- Red Hat OpenShift Container Platform 4

Not affected:

- Red Hat Enterprise Linux 6

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture.

Because of this proactive approach, a patch may be associa… https://access.redhat.com/errata/RHSA-2026:71687
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture.

Because of this proactive approach, a patch may be associa… https://access.redhat.com/errata/RHSA-2026:71657
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture.

Because of this proactive approach, a patch may be associa… https://access.redhat.com/errata/RHSA-2026:71599

Workarounds / mitigations:

- See the security bulletin for a detailed mitigation procedure.
