KernelScan.io

HIGH Public exploit Introduced in 4.6

TUNderflow

CVE-2026-81000

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.6HIGH

01

In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the result becomes negative when stored in good_linear. That value later wraps when assigned to the size_t linear variable, and tun_alloc_skb() can place skb->data outside the allocated head. Bound the headroom stored by TUN to the one-page skb-head budget and the largest non-sentinel 16-bit skb header offset. Leave one linear byte for raw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN. Also pull the raw-TUN protocol byte and the TAP Ethernet header before accessing them, so these checks remain safe for nonlinear skbs supplied by other allocation paths.

02

Engine v0.6.0

Risk summary

An unprivileged local user who can obtain CAP_NET_ADMIN inside a user namespace can trigger an integer underflow in the TUN/TAP driver's receive headroom calculation, causing an out-of-bounds write in kernel memory. This is a container-escape risk on multi-tenant systems where tenants can create network namespaces and TUN devices. The corruption can lead to arbitrary kernel read/write and system crash.

Affecteddrivers/net/tun.c (TUN/TAP virtual network driver)

Vulnerability analysis

The TUN/TAP driver stores a receive headroom value that can be propagated from external sources such as Open vSwitch or the network core forwarding path. When this headroom exceeds the usable space in a standard single-page kernel packet buffer, an arithmetic underflow occurs in the linear-data-size calculation: the result wraps to a very large value, causing the packet allocator to place the data pointer outside the allocated buffer. Subsequent packet writes then corrupt adjacent kernel heap memory. The fix clamps the stored headroom to a safe maximum derived from the kernel's buffer budget and adds checks to ensure packet headers are present in linear space before being read. The vulnerable path is reachable by any caller with CAP_NET_ADMIN in a network namespace — including unprivileged processes inside a user namespace — making it a container-escape risk on multi-tenant or container-host systems.

Exploit availability

KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.

03

BranchIntroducedFixed inPatch commit
6.64.66.6.157010eee265d6b
7.24.67.2.40ada54ea63e4
5.104.65.10.270ad715e713610
5.154.65.15.221708e87937de9
6.14.66.1.18818ef24cdb2eb
6.124.66.12.109379d85c7f25f
mainline4.67.3-rc1447c9303942c
6.184.66.18.50e098d9cc8859