CVE-2026-81000

HIGHCVSS 7.8/10EPSS 0.16%

Last modified

CVE-2026-81000 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the result becomes negative when stored in good_linear. EPSS estimates a 0.16% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the result becomes negative when stored in good_linear. That value later wraps when assigned to the size_t linear variable, and tun_alloc_skb() can place skb->data outside the allocated head. Bound the headroom stored by TUN to the one-page skb-head budget and the largest non-sentinel 16-bit skb header offset. Leave one linear byte for raw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN. Also pull the raw-TUN protocol byte and the TAP Ethernet header before accessing them, so these checks remain safe for nonlinear skbs supplied by other allocation paths.

Metrics

EPSS Probability
0.16%

5.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= eaea34b23c46bf17b4a5638be69ab3561854f34b, < ad715e713610d2d5473c3a6498c825ccecf26491; >= eaea34b23c46bf17b4a5638be69ab3561854f34b, < 708e87937de93f445225c134a2e20519f9b4ce60; >= eaea34b23c46bf17b4a5638be69ab3561854f34b, < 18ef24cdb2eba32e38f1d27f2d02b7b4212e8f76; >= eaea34b23c46bf17b4a5638be69ab3561854f34b, < 010eee265d6bd8769b6a523d2a0693d9b3f5df43; >= eaea34b23c46bf17b4a5638be69ab3561854f34b, < 379d85c7f25f3e05a428225e6b8a65613c6e9b9d; >= eaea34b23c46bf17b4a5638be69ab3561854f34b, < e098d9cc8859614a7f7baebc96e32a5a16b18ed2; >= eaea34b23c46bf17b4a5638be69ab3561854f34b, < 0ada54ea63e48b9c1608e917ccb7dfadbe86db28; >= eaea34b23c46bf17b4a5638be69ab3561854f34b, < 447c9303942c439a117d9b76ce6d6e2116b38ee7
LinuxLinux4.6

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-81000?
In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the result becomes negative when stored in good_linear. That value later wraps when assigned to the size_t linear variable, and tun_alloc_skb() can place skb->data outside the allocated head. Bound the headroom stored by TUN to the one-page skb-head budget and the largest non-sentinel 16-bit skb header offset. Leave one linear byte for raw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN. Also pull the raw-TUN protocol byte and the TAP Ethernet header before accessing them, so these checks remain safe for nonlinear skbs supplied by other allocation paths.
How severe is CVE-2026-81000?
CVE-2026-81000 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.16% probability of exploitation in the next 30 days.
How do I fix CVE-2026-81000?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-81000?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST