HIGH Public exploit Introduced in 4.6
TUNderflow
CVE-2026-81000
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.6HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the result becomes negative when stored in good_linear. That value later wraps when assigned to the size_t linear variable, and tun_alloc_skb() can place skb->data outside the allocated head. Bound the headroom stored by TUN to the one-page skb-head budget and the largest non-sentinel 16-bit skb header offset. Leave one linear byte for raw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN. Also pull the raw-TUN protocol byte and the TAP Ethernet header before accessing them, so these checks remain safe for nonlinear skbs supplied by other allocation paths.
02KernelScan AI Analysis
Risk summary
An unprivileged local user who can obtain CAP_NET_ADMIN inside a user namespace can trigger an integer underflow in the TUN/TAP driver's receive headroom calculation, causing an out-of-bounds write in kernel memory. This is a container-escape risk on multi-tenant systems where tenants can create network namespaces and TUN devices. The corruption can lead to arbitrary kernel read/write and system crash.
Vulnerability analysis
The TUN/TAP driver stores a receive headroom value that can be propagated from external sources such as Open vSwitch or the network core forwarding path. When this headroom exceeds the usable space in a standard single-page kernel packet buffer, an arithmetic underflow occurs in the linear-data-size calculation: the result wraps to a very large value, causing the packet allocator to place the data pointer outside the allocated buffer. Subsequent packet writes then corrupt adjacent kernel heap memory. The fix clamps the stored headroom to a safe maximum derived from the kernel's buffer budget and adds checks to ensure packet headers are present in linear space before being read. The vulnerable path is reachable by any caller with CAP_NET_ADMIN in a network namespace — including unprivileged processes inside a user namespace — making it a container-escape risk on multi-tenant or container-host systems.
Exploit availability
KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.6 | 4.6 | 6.6.157 | 010eee265d6b |
| 7.2 | 4.6 | 7.2.4 | 0ada54ea63e4 |
| 5.10 | 4.6 | 5.10.270 | ad715e713610 |
| 5.15 | 4.6 | 5.15.221 | 708e87937de9 |
| 6.1 | 4.6 | 6.1.188 | 18ef24cdb2eb |
| 6.12 | 4.6 | 6.12.109 | 379d85c7f25f |
| mainline | 4.6 | 7.3-rc1 | 447c9303942c |
| 6.18 | 4.6 | 6.18.50 | e098d9cc8859 |