CVE-2026-63994
Last modified
CVE-2026-63994 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() Sashiko found that iptunnel_pmtud_build_icmp() and iptunnel_pmtud_build_icmpv6() were caching ip_hdr() and ipv6_hdr() before an skb_cow() call which can reallocate skb->head. Fix this possible UAF by initializing the local variables after the skb_cow() call. Remove skb_reset_network_header() calls which were not needed.. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() Sashiko found that iptunnel_pmtud_build_icmp() and iptunnel_pmtud_build_icmpv6() were caching ip_hdr() and ipv6_hdr() before an skb_cow() call which can reallocate skb->head. Fix this possible UAF by initializing the local variables after the skb_cow() call. Remove skb_reset_network_header() calls which were not needed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < 95b6d772bfe788331d9742d73eaa12e113b2adc4; >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < 7254aef4d1a7e18e887af9010e2f2dc34806789b; >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < bf8b3f34c37c162357138e7c0942723b8b94fed1; >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < 76cd9398a0470257ab765bdf5f358a2af2e17934; >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < 50750d86a2e5266aba0c295483b3397843198b11; >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < 6dff77899b9e9fe5d854abda3a98ad04e7229ef7; >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < f3f204541f280a6ecb04503a0d6794d93990ca43; >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < b4bc94353050b1fa7b702bd4c6600710dd926cff |
| Linux | Linux | 5.9 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-63994?
How severe is CVE-2026-63994?
How do I fix CVE-2026-63994?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63989In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6399The General Options plugin for WordPress is vulnerable to St…4.4
- CVE-2026-63990In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63991In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63992In the Linux kernel, the following vulnerability has been re…9.1
- CVE-2026-63993In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-63995In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-63996In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-63997In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63998In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63999In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6400The Child Height Predictor by Ostheimer plugin for WordPress…4.3
Are you affected by CVE-2026-63994?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
