SB20260912214 - Incorrect calculation in Linux kernel ipv6



SB20260912214 - Incorrect calculation in Linux kernel ipv6

Published: September 12, 2026

Security Bulletin ID SB20260912214
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect calculation (CVE-ID: CVE-2026-89562)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect tunnel hardware header length handling.

The vulnerability exists due to improper hardware header length calculation in ip6_gre tunnel configuration when configuring an NBMA ip6gre tunnel. A local user can configure an NBMA ip6gre tunnel to cause incorrect tunnel hardware header length handling.

ip6gretap and ip6erspan use fixed Ethernet hardware header lengths.


Remediation

Install update from vendor's website.