CVE-2026-63991

UnknownEPSS 0.18%

Last modified

CVE-2026-63991 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() The skb_clone() function can return NULL if memory allocation fails. send_mcast_pkt() calls skb_clone() without checking the return value, which can lead to a NULL pointer dereference in send_pkt() when it dereferences skb->data. Add a NULL check after skb_clone() and skip the peer if the clone fails.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() The skb_clone() function can return NULL if memory allocation fails. send_mcast_pkt() calls skb_clone() without checking the return value, which can lead to a NULL pointer dereference in send_pkt() when it dereferences skb->data. Add a NULL check after skb_clone() and skip the peer if the clone fails.

Metrics

EPSS Probability
0.18%

7.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 18722c247023035b9e2e2a08a887adec2a9a6e49, < 9afcb5ea080af13aab37930da627db43bd277665; >= 18722c247023035b9e2e2a08a887adec2a9a6e49, < 9903a04becf059e44cccf625e23689b7d4378384; >= 18722c247023035b9e2e2a08a887adec2a9a6e49, < d630c4b25f36e0e68461561e4c70957ec37fdedd; >= 18722c247023035b9e2e2a08a887adec2a9a6e49, < b06203ac5f12929d79146bb9f063c2af1d679e63; >= 18722c247023035b9e2e2a08a887adec2a9a6e49, < 3d5d81d294ba09487c86bc4ba33dc4a4bec5d215; >= 18722c247023035b9e2e2a08a887adec2a9a6e49, < e673889a35a5e4c586d0fae67d8755ca4367d3e2; >= 18722c247023035b9e2e2a08a887adec2a9a6e49, < 2061d080a013c0ec0a56162cd501fb36d2befc26; >= 18722c247023035b9e2e2a08a887adec2a9a6e49, < 3c40d381ce04f9575a5d8b542898183c3b4b38dc
LinuxLinux3.14

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-63991?
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() The skb_clone() function can return NULL if memory allocation fails. send_mcast_pkt() calls skb_clone() without checking the return value, which can lead to a NULL pointer dereference in send_pkt() when it dereferences skb->data. Add a NULL check after skb_clone() and skip the peer if the clone fails.
How severe is CVE-2026-63991?
Severity scoring for CVE-2026-63991 is pending analysis. The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2026-63991?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-63991?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST