Junglewise Threat Intelligence

CVE-2026-52940: Linux Kernel information leak in TUN driver tun_put_user

CVE-2026-52940 · Severity: info · CVSS 3.3 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's network TUN driver could allow a local user to view sensitive information from the system's memory. By manipulating network header settings, an attacker can cause the system to leak small amounts of internal kernel data during normal network operations. This could potentially expose cryptographic keys or other sensitive data belonging to the operating system or other users.

Technical details

An information leak exists in the Linux kernel TUN driver (drivers/net/tun.c) within the tun_put_user() function. The function declares a 'virtio_net_hdr_v1_hash_tunnel' structure on the stack but fails to zero-initialize it. When processing non-tunnel packets, only the first 10 bytes are initialized, leaving the remaining 14 bytes containing residual stack data. By using the TUNSETVNETHDRSZ ioctl to set the header size to 24 bytes, an unprivileged local user can force the kernel to copy the uninitialized bytes to userspace during packet reads. This has been fixed by adding a memset() call to zero the header structure upon declaration.

Affected products

  • Linux Linux Kernel 6.17 to 6.18.36, 7.0 to 7.0.13

Timeline

  • 2026-06-06: other: Vulnerability reported by Weiming Shi
  • 2026-06-09: patched: Fix committed to mainline kernel
  • 2026-06-24: advisory: CVE-2026-52940 published

References

Related threats