Incorrect calculation in Linux kernel - CVE-2026-89562
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause incorrect tunnel hardware header length handling.
The vulnerability exists due to improper hardware header length calculation in ip6_gre tunnel configuration when configuring an NBMA ip6gre tunnel. A local user can configure an NBMA ip6gre tunnel to cause incorrect tunnel hardware header length handling.
ip6gretap and ip6erspan use fixed Ethernet hardware header lengths.