Memory Management Flaw in Linux Kernel Networking Component
CVE-2026-63993
What is CVE-2026-63993?
A memory management vulnerability was identified in the Linux kernel related to the vxlan networking component. The flaw occurs due to improper handling of the skb->head values, specifically after the skb_tunnel_check_pmtu() function is called. This function changes the structure of the socket buffer, leading to a potential use-after-free condition if older ip_hdr values are incorrectly reused. The security issue can cause erratic kernel behavior and predictable memory accesses, which could be potentially exploited. It is advised to update to the latest version where this issue has been resolved.
Affected Version(s)
Linux 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 6b8bfce9d2f774d2c2243e0248e03efb99bba6c0
Linux 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 9257f56ac47ef1976bcd056cf986a9988eeec67a
Linux 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 8d435d68d71fb875876b722f4136caf74f2f48bd