Integer underflow in Linux kernel - CVE-2026-81000

 

Integer underflow in Linux kernel - CVE-2026-81000

Published: September 12, 2026


Vulnerability identifier: #VU149394
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-81000
CWE-ID: CWE-191
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to write packet data outside allocated memory.

The vulnerability exists due to an integer underflow in TUN and TAP interface handling in tun_get_user() when processing an oversized headroom request propagated by an OVS port. A local user can configure an OVS port to propagate an oversized headroom request to a TUN or TAP device to write packet data outside allocated memory.


Affected software

Linux kernel
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
kernel-rt (Red Hat package)

How to mitigate CVE-2026-81000

Install security update from vendor's repository.

kernel-rt (Red Hat package) - update to 4.18.0-553.167.1.rt7.508.el8_10

External References

Related Security Bulletins