Out-of-Bound Access in Linux Kernel Affecting Transport Header Processing
CVE-2026-63992

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63992?

A vulnerability exists in the Linux kernel's handling of transport headers in the iptunnel_pmtud_check_icmp() function. This flaw may result in out-of-bounds access when the skb transport header is not properly set. Such conditions can lead to security risks as the function attempts to access data based on the IPv4 network header without ensuring that the required ICMP type is present in the skb linear part. The vulnerability has been addressed in recent updates, ensuring improved handling of transport headers.

Affected Version(s)

Linux 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 5a92cb45e34749865d03daf8d3500f77b5f6644c

Linux 4cb47a8644cc9eb8ec81190a50e79e6530d0297f

Linux 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 7f4f7efe7f30edd29c4988de01728bf2398217e4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.