CVE-2026-63924
A critical flaw was discovered in the Linux kernel’s IPv6 packet handling. The bug could let an attacker send crafted packets that crash the kernel or potentially run arbitrary code. The issue has been fixed in a kernel update.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users running versions before the patch, including system administrators and operators of Linux servers and devices.
Real-world impact
An attacker could send specially crafted IPv6 packets that trigger the flaw, causing the kernel to crash (denial of service) or, in worst cases, execute code with kernel privileges.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is network‑exploitable, requires no user interaction, and can compromise confidentiality, integrity, and availability of the affected system.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for CVE-2026-63924.
NVD description indicates the vulnerability has been resolved.
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 27, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/2b56bbd928c030894c…
- git.kernel.org/stable/c/645b99b1a185c91a79…
- git.kernel.org/stable/c/72af7beae774e46ed5…
- git.kernel.org/stable/c/9e883eaa878f4337b5…
- git.kernel.org/stable/c/b3ac54e5c905f86d22…
- git.kernel.org/stable/c/bddaa4dfc7f36e1ee3…
- git.kernel.org/stable/c/c512e1c819dfbf6ae9…
- git.kernel.org/stable/c/d47548a36639095939…