CVE-2026-63993: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 6.12.111-1Fixed in 7.2.8-1 - Compensating control
In the Linux kernel VXLAN code, use ip_hdr(skb) after skb_tunnel_check_pmtu() instead of reusing the cached ip_hdr() value (old_iph), because skb_tunnel_check_pmtu() can change skb->head.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63993?
The severity of CVE-2026-63993 is critical with a CVSS score of 9.8.
How do I fix CVE-2026-63993?
To fix CVE-2026-63993, update your Linux Kernel to the latest patched version that addresses this vulnerability.
What kind of impact does CVE-2026-63993 have on systems?
CVE-2026-63993 can lead to a use-after-free condition, potentially allowing an attacker to execute arbitrary code.
Which software is affected by CVE-2026-63993?
CVE-2026-63993 affects the Linux Kernel, specifically in its handling of VXLAN IP headers.
When was CVE-2026-63993 disclosed?
CVE-2026-63993 was published on July 19, 2026.