Kernel Stack Overflow Due to Blockcast Recursion in Linux Kernel
CVE-2026-63981

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63981?

A vulnerability in the Linux kernel allows an unprivileged user to exploit a flaw in the tcf_mirred_act function. This flaw can lead to an unbounded recursion loop when mirroring packets using blockcast rules across two devices. The function fails to appropriately track recursion depth, leading to a stack overflow condition. By leveraging user namespaces to gain CAP_NET_ADMIN privileges, attackers can create dummy devices and install malicious mirred blockcast filters to exploit this vulnerability, ultimately causing kernel panic and disruption of system stability.

Affected Version(s)

Linux 906736728cea480a85803c67fafb1b0e78491922 < 25fc9352590f5ef21ebf290432bd768b336693bc

Linux fe946a751d9b52b7c45ca34899723b314b79b249 < 34457de389fb64a01fdcc71177dfebe65fd2d362

Linux fe946a751d9b52b7c45ca34899723b314b79b249

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.