Executive brief
IP tunnel devices in the Linux kernel can advertise excessive memory headroom requirements when stacked multiple times, causing 16-bit buffer offset fields to wrap around during packet transmission. An attacker with local access can create nested tunnel configurations to trigger buffer overflows in packet handling, potentially crashing the system or executing arbitrary kernel code.
Technical details
The vulnerability is an integer overflow in the Linux kernel's IP tunnel (IPv4, IPv6 GRE, IPv6 tunnel, and SIT) implementation. When tunnel devices derive their advertised needed_headroom from lower-layer devices, stacking user-created tunnels can produce headroom values exceeding the 65,535-byte limit of 16-bit skb header offset fields. This causes skb_headers_offset_update() to wrap those offsets during IP output processing. The fix caps advertised headroom at 512 bytes, matching the runtime transmit path's existing limit. The vulnerability requires local network namespace capabilities and tunnel configuration privileges; remote exploitation is not possible. A patch has been committed upstream and is being backported to stable kernel series.
Affected products
- Linux Linux kernel 2.6.11 through 7.2 (all stable branches)
Timeline
- 2026-09-11: disclosed: Vulnerability publicly disclosed via NVD
- 2026-08-18: patched: Upstream patch merged (commit 6b222adeb934) by Paolo Abeni
- 2026-09-14: patched: Backport merged to stable trees by Greg Kroah-Hartman (commit 84783961cb8b)