« Back to list

CVE-2026-80978

Status: ReceivedHigh (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

net: cap advertised IP tunnel headroom

IP tunnel devices derive their advertised needed_headroom from lower output devices. A stack of user-created devices can make the derived value larger than the 16-bit skb header offsets can represent. Once IP output reserves it, skb head expansion can wrap those offsets.

The runtime transmit path already caps a growing needed_headroom at 512. Apply the same cap when tunnel configuration publishes needed_headroom derived from a lower output device.

Capping the advertised value is safe: IP tunnel transmit still expands the skb when a packet needs more headroom. A nonsensical stacked configuration can therefore incur an extra reallocation, but it cannot publish an unbounded reservation to upper layers.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Escalada de privilegios local (AV:L, PR:L, UI:N) en kernel Linux mediante manipulación de headroom en túneles IP causando corrupción de memoria (DoS o integridad de datos).

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-80978",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1a37e412a0225fcba5587f24c0dfc7636efc8b69",
              "lessThan": "fb889a619723032140f5d983a3a34d25a5a2bed4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a37e412a0225fcba5587f24c0dfc7636efc8b69",
              "lessThan": "b160422f8103574425e2834130e169d84c94fa1d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a37e412a0225fcba5587f24c0dfc7636efc8b69",
              "lessThan": "d36e75f5669140b66515ad3a176ca6337bd80a5e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a37e412a0225fcba5587f24c0dfc7636efc8b69",
              "lessThan": "84783961cb8bdb36b4f41a02ce43aafc6d52b176",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a37e412a0225fcba5587f24c0dfc7636efc8b69",
              "lessThan": "bc4e05ae66c9797a0972ac44326e69c5305e0020",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a37e412a0225fcba5587f24c0dfc7636efc8b69",
              "lessThan": "af0ee8f04bea22cdb331fa3509e17f81b48938ad",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a37e412a0225fcba5587f24c0dfc7636efc8b69",
              "lessThan": "9144f2c53a04465a6878172b523f640313c5559e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a37e412a0225fcba5587f24c0dfc7636efc8b69",
              "lessThan": "6b222adeb9340306e2ff97127c76117abb9b3df8",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "include/net/ip_tunnels.h",
            "net/ipv4/ip_tunnel.c",
            "net/ipv6/ip6_gre.c",
            "net/ipv6/ip6_tunnel.c",
            "net/ipv6/sit.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/net/ip_tunnels.h",
            "net/ipv4/ip_tunnel.c",
            "net/ipv6/ip6_gre.c",
            "net/ipv6/ip6_tunnel.c",
            "net/ipv6/sit.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:04.143",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/6b222adeb9340306e2ff97127c76117abb9b3df8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/84783961cb8bdb36b4f41a02ce43aafc6d52b176",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9144f2c53a04465a6878172b523f640313c5559e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/af0ee8f04bea22cdb331fa3509e17f81b48938ad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b160422f8103574425e2834130e169d84c94fa1d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bc4e05ae66c9797a0972ac44326e69c5305e0020",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d36e75f5669140b66515ad3a176ca6337bd80a5e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fb889a619723032140f5d983a3a34d25a5a2bed4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: cap advertised IP tunnel headroom\n\nIP tunnel devices derive their advertised needed_headroom from lower\noutput devices. A stack of user-created devices can make the derived\nvalue larger than the 16-bit skb header offsets can represent. Once IP\noutput reserves it, skb head expansion can wrap those offsets.\n\nThe runtime transmit path already caps a growing needed_headroom at 512.\nApply the same cap when tunnel configuration publishes needed_headroom\nderived from a lower output device.\n\nCapping the advertised value is safe: IP tunnel transmit still expands\nthe skb when a packet needs more headroom. A nonsensical stacked\nconfiguration can therefore incur an extra reallocation, but it cannot\npublish an unbounded reservation to upper layers."
    }
  ],
  "lastModified": "2026-09-14T13:18:52.650",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}