SB20260912214 - Incorrect calculation in Linux kernel ipv6
Published: September 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect calculation (CVE-ID: CVE-2026-89562)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause incorrect tunnel hardware header length handling.
The vulnerability exists due to improper hardware header length calculation in ip6_gre tunnel configuration when configuring an NBMA ip6gre tunnel. A local user can configure an NBMA ip6gre tunnel to cause incorrect tunnel hardware header length handling.
ip6gretap and ip6erspan use fixed Ethernet hardware header lengths.
Remediation
Install update from vendor's website.