In the Linux kernel, the following vulnerability has been resolved: net: cap advertised IP tunnel headroom IP tunnel devices derive their advertised… (CVE-2026-80978)
A vulnerability in the Linux kernel's IP tunnel devices was resolved. The issue involved the advertised needed_headroom value derived from lower output devices, which could become larger than the 16-bit skb header offsets can represent, causing offset wrapping during skb head expansion. The fix caps the advertised needed_headroom value to prevent this wraparound. This mitigation ensures safe operation even with complex stacked device configurations.
AI Analysis
Technical Summary
The Linux kernel IP tunnel devices derive their advertised needed_headroom from lower output devices. When multiple user-created devices are stacked, the derived needed_headroom value can exceed the representable range of 16-bit skb header offsets, leading to offset wrapping during skb head expansion in the IP output path. Although the runtime transmit path already caps needed_headroom growth at 512, the vulnerability was that the tunnel configuration could publish an unbounded needed_headroom value. The fix applies the same cap at the configuration stage, preventing the advertised value from exceeding 512. This prevents skb header offset wraparound and potential memory corruption or instability. The fix is safe and may cause extra reallocations in nonsensical stacked configurations but avoids unbounded reservations.
Potential Impact
If unmitigated, the vulnerability could cause skb header offset wraparound due to oversized needed_headroom values in IP tunnel devices, potentially leading to memory corruption or kernel instability. The fix caps the advertised needed_headroom, preventing this condition. There are no known exploits in the wild. The impact is limited to kernel networking stack behavior with complex stacked IP tunnel devices.
Mitigation Recommendations
A fix has been applied in the Linux kernel to cap the advertised needed_headroom value at 512 during tunnel configuration, preventing offset wraparound. Users should update to the patched kernel version containing this fix. No additional mitigation is required as the runtime transmit path already caps needed_headroom, and the fix ensures safe operation.
In the Linux kernel, the following vulnerability has been resolved: net: cap advertised IP tunnel headroom IP tunnel devices derive their advertised… (CVE-2026-80978)
Description
A vulnerability in the Linux kernel's IP tunnel devices was resolved. The issue involved the advertised needed_headroom value derived from lower output devices, which could become larger than the 16-bit skb header offsets can represent, causing offset wrapping during skb head expansion. The fix caps the advertised needed_headroom value to prevent this wraparound. This mitigation ensures safe operation even with complex stacked device configurations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel IP tunnel devices derive their advertised needed_headroom from lower output devices. When multiple user-created devices are stacked, the derived needed_headroom value can exceed the representable range of 16-bit skb header offsets, leading to offset wrapping during skb head expansion in the IP output path. Although the runtime transmit path already caps needed_headroom growth at 512, the vulnerability was that the tunnel configuration could publish an unbounded needed_headroom value. The fix applies the same cap at the configuration stage, preventing the advertised value from exceeding 512. This prevents skb header offset wraparound and potential memory corruption or instability. The fix is safe and may cause extra reallocations in nonsensical stacked configurations but avoids unbounded reservations.
Potential Impact
If unmitigated, the vulnerability could cause skb header offset wraparound due to oversized needed_headroom values in IP tunnel devices, potentially leading to memory corruption or kernel instability. The fix caps the advertised needed_headroom, preventing this condition. There are no known exploits in the wild. The impact is limited to kernel networking stack behavior with complex stacked IP tunnel devices.
Mitigation Recommendations
A fix has been applied in the Linux kernel to cap the advertised needed_headroom value at 512 during tunnel configuration, preventing offset wraparound. Users should update to the patched kernel version containing this fix. No additional mitigation is required as the runtime transmit path already caps needed_headroom, and the fix ensures safe operation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-p2qp-rm9g-w8f3
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-80978"]
Threat ID: 6aa4a02c55bf5e2cf5a86b5a
Added to database: 09/12/2026, 00:43:24 UTC
Last enriched: 09/12/2026, 01:23:36 UTC
Last updated: 09/12/2026, 03:01:24 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.