CVE-2026-63857
A bug in the Linux kernel’s airoha network driver could cause an unsafe read of uninitialized memory during packet transmission, potentially leading to a crash. The issue has been fixed by preventing the read on the last iteration and adjusting packet descriptor handling. Users should update their kernel to a version that includes this patch.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, specifically the airoha network driver. Systems running kernel versions before the patch that includes the fix for CVE-2026-63857 are affected.
Real-world impact
An attacker could trigger a crash or denial of service by sending crafted network traffic that causes the kernel to read uninitialized memory during packet transmission, potentially forcing a system reboot or loss of service.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is exploitable over the network with no authentication or user interaction, and it can compromise confidentiality, integrity, and availability, making it a critical issue.
What to do about it
- 01Update the Linux kernel to a version that includes the fix for CVE-2026-63857.
- 02Reboot the system to load the new kernel.
NVD description indicates the issue has been resolved in the kernel
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 27, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.