Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-81000 — Research repository for CVE-2026-81000 (TUNderflow), a Linux kernel TUN/TAP receive headroom integer underflow enabling local privilege escalation, with PoC, root-cause analysis, and lab setup. | Kitploit
도구/GitHubGitHub/0xblackash/cve-2026-81000
Privilege EscalationVulnerability AnalysisExploitationReverse EngineeringPenetration TestingPapers & ResearchLearning & EducationBinary ExploitationLabs & Practice
GitHub0xblackash/cve-2026-81000

CVE-2026-81000

Research repository for CVE-2026-81000 (TUNderflow), a Linux kernel TUN/TAP receive headroom integer underflow enabling local privilege escalation, with PoC, root-cause analysis, and lab setup.

17111일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

⚡ CVE-2026-81000 - TUNderflow

Gemini_Generated_Image_tewwjgtewwjgteww

Linux Kernel TUN/TAP Receive Headroom Memory Corruption

A Linux kernel memory-corruption vulnerability in the TUN/TAP networking subsystem, caused by insufficient bounds on receive headroom and an integer underflow in the packet allocation path.


⚠️ Disclaimer

This repository is intended for authorized security research, vulnerability analysis, CTF environments, kernel debugging, and defensive testing.

Do not use proof-of-concept code against systems without explicit authorization.


📌 Vulnerability Overview

FieldDetails
CVECVE-2026-81000
CodenameTUNderflow
ComponentLinux Kernel
SubsystemTUN/TAP
Affected Codedrivers/net/tun.c
Primary Functiontun_get_user()
Bug ClassInteger underflow / out-of-bounds memory access
ImpactKernel memory corruption
Potential ImpactLocal privilege escalation
CVSS v3.17.8 — High
Attack VectorLocal
Privileges RequiredLow
User InteractionNone
StatusPatched

The CVE advisory describes the issue as an integer underflow that can cause skb->data to be positioned outside the allocated skb head.


🧬 Vulnerability Description

The vulnerability exists in the Linux kernel's TUN/TAP receive path.

The affected code uses the TUN device's configured receive headroom both as packet headroom and when calculating how much packet data should remain linear.

An oversized headroom value can therefore create an invalid calculation in:

SKB_MAX_HEAD(align)

When the supplied value exceeds the usable one-page skb head, the calculation can underflow.

Conceptually:

Oversized receive headroom
          │
          ▼
     SKB_MAX_HEAD()
          │
          ▼
     Integer underflow
          │
          ▼
    Negative value
          │
          ▼
      size_t wrap
          │
          ▼
Invalid skb data placement
          │
          ▼
Kernel memory corruption

The vulnerable implementation is located in:

drivers/net/tun.c

with tun_get_user() being central to the vulnerable path.


🔬 Root Cause

The underlying problem is insufficiently bounded TUN receive headroom.

The kernel can receive an oversized headroom request through network-device paths that propagate the value to TUN/TAP.

The vulnerability becomes particularly interesting when a complex virtual networking configuration causes a large headroom value to reach a TUN device.

The public disclosure describes a scenario involving:

Netkit
   │
   ▼
VXLAN
   │
   ▼
Open vSwitch
   │
   ▼
TUN

An example configuration can propagate approximately 4160 bytes of headroom to a raw TUN port, causing the vulnerable arithmetic to underflow.


💥 Security Impact

The corruption occurs in kernel networking memory-management logic.

Potential consequences include:

  • Kernel memory corruption
  • Kernel crash
  • Denial of service
  • Corruption of kernel structures
  • Potential kernel code execution
  • Local privilege escalation

The public disclosure reports the vulnerability as one of a group of Linux local-root vulnerabilities and states that the published PoC can achieve unprivileged local user-to-root execution on supported targets.

Exploitability is environment-dependent and requires the relevant TUN/network device configuration and supporting functionality.


🧠 Technical Flow

             ATTACKER
                 │
                 ▼
       Oversized network headroom
                 │
                 ▼
        Virtual network device
                 │
                 ▼
             Open vSwitch
                 │
                 ▼
              TUN/TAP
                 │
                 ▼
          tun_get_user()
                 │
                 ▼
       SKB_MAX_HEAD(align)
                 │
                 ▼
          Integer underflow
                 │
                 ▼
          size_t wraparound
                 │
                 ▼
       Invalid skb->data offset
                 │
                 ▼
       Kernel memory corruption

🔎 Vulnerable Code Path

The important components are:

drivers/net/tun.c
        │
        ├── tun_set_headroom()
        │
        ├── tun_get_user()
        │
        └── tun_alloc_skb()

The vulnerable relationship can be simplified as:

tun->align
    │
    ├── skb headroom
    │
    └── linear-data calculation

Using the same oversized value in both calculations creates an unsafe relationship between the requested headroom and the actual skb head budget.


🧮 Integer Underflow

The critical security property can be represented conceptually as:

usable_head < requested_headroom

which can result in:

SKB_MAX_HEAD(align) < 0

followed by an unsigned conversion:

negative value
      ↓
size_t
      ↓
very large unsigned value

This can ultimately influence skb allocation/data placement.

The official description specifically notes that the resulting value wraps when assigned to the size_t linear variable.


🩹 Upstream Fix

The upstream fix is:

447c9303942c439a117d9b76ce6d6e2116c38ee7

Commit:

net: tun: bound receive headroom

The fix bounds the headroom stored by TUN against the available one-page skb head budget and the largest valid 16-bit skb header offset. It also ensures sufficient linear data is available for raw TUN and TAP processing.


🛡️ Patch Concept

Before

User / network device
        │
        ▼
Large headroom
        │
        ▼
tun->align
        │
        ▼
Unsafe arithmetic
        │
        ▼
Potential OOB access

After

User / network device
        │
        ▼
Large headroom
        │
        ▼
Bounded headroom
        │
        ▼
Safe skb calculation
        │
        ▼
Normal packet processing

📊 Vulnerable vs Patched

도구 다운로드