Integer underflow in Linux kernel - CVE-2026-81000
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to write packet data outside allocated memory.
The vulnerability exists due to an integer underflow in TUN and TAP interface handling in tun_get_user() when processing an oversized headroom request propagated by an OVS port. A local user can configure an OVS port to propagate an oversized headroom request to a TUN or TAP device to write packet data outside allocated memory.
Affected software
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
kernel-rt (Red Hat package)