CVE-2026-63994

Source
https://cve.org/CVERecord?id=CVE-2026-63994
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63994.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63994
Downstream
Published
2026-07-19T14:56:13.896Z
Modified
2026-07-22T05:30:07.588610205Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
Details

In the Linux kernel, the following vulnerability has been resolved:

tunnels: load network headers after skbcow() in iptunnelpmtudbuildicmpv6

Sashiko found that iptunnelpmtudbuildicmp() and iptunnelpmtudbuildicmpv6() were caching iphdr() and ipv6hdr() before an skb_cow() call which can reallocate skb->head.

Fix this possible UAF by initializing the local variables after the skb_cow() call.

Remove skbresetnetwork_header() calls which were not needed.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63994.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4cb47a8644cc9eb8ec81190a50e79e6530d0297f
Fixed
95b6d772bfe788331d9742d73eaa12e113b2adc4
Fixed
7254aef4d1a7e18e887af9010e2f2dc34806789b
Fixed
bf8b3f34c37c162357138e7c0942723b8b94fed1
Fixed
76cd9398a0470257ab765bdf5f358a2af2e17934
Fixed
50750d86a2e5266aba0c295483b3397843198b11
Fixed
6dff77899b9e9fe5d854abda3a98ad04e7229ef7
Fixed
f3f204541f280a6ecb04503a0d6794d93990ca43
Fixed
b4bc94353050b1fa7b702bd4c6600710dd926cff

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63994.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.9.0
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63994.json"