Memory Management Flaw in Linux Kernel Networking Component
CVE-2026-63993

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63993?

A memory management vulnerability was identified in the Linux kernel related to the vxlan networking component. The flaw occurs due to improper handling of the skb->head values, specifically after the skb_tunnel_check_pmtu() function is called. This function changes the structure of the socket buffer, leading to a potential use-after-free condition if older ip_hdr values are incorrectly reused. The security issue can cause erratic kernel behavior and predictable memory accesses, which could be potentially exploited. It is advised to update to the latest version where this issue has been resolved.

Affected Version(s)

Linux 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 6b8bfce9d2f774d2c2243e0248e03efb99bba6c0

Linux 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 9257f56ac47ef1976bcd056cf986a9988eeec67a

Linux 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 8d435d68d71fb875876b722f4136caf74f2f48bd

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.