Incorrect calculation in Linux kernel - CVE-2026-89562

 

Incorrect calculation in Linux kernel - CVE-2026-89562

Published: September 12, 2026


Vulnerability identifier: #VU149236
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89562
CWE-ID: CWE-682
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause incorrect tunnel hardware header length handling.

The vulnerability exists due to improper hardware header length calculation in ip6_gre tunnel configuration when configuring an NBMA ip6gre tunnel. A local user can configure an NBMA ip6gre tunnel to cause incorrect tunnel hardware header length handling.

ip6gretap and ip6erspan use fixed Ethernet hardware header lengths.


Affected software

Linux kernel

How to mitigate CVE-2026-89562

Install security update from vendor's repository.


External References

Related Security Bulletins