CVE-2026-63984
A flaw in the Linux kernel's IPv6 processing allows for a memory corruption error during the decompression of routing headers. This occurs when a specific number of address segments causes a calculation error, leading to data being written into the wrong memory location.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running affected versions of the Linux kernel that process IPv6 routing headers.
Real-world impact
An attacker could send specially crafted IPv6 packets to cause memory corruption, potentially leading to system instability or the corruption of network traffic being forwarded by the system.
Why this severity
The critical score reflects that this vulnerability is remotely exploitable over the network without requiring any user interaction or special privileges, and it can impact the confidentiality, integrity, and availability of the system.
What to do about it
- 01Update the Linux kernel to the version containing the fix for ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress().
NVD-referenced vendor advisory
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/3618b34942b76471d0…
- git.kernel.org/stable/c/6fe1cb312038516cb4…
- git.kernel.org/stable/c/75b3680047bf09af8e…
- git.kernel.org/stable/c/97e06791368c01f0ad…
- git.kernel.org/stable/c/9d5e7a46a9f6d8f503…
- git.kernel.org/stable/c/c0487a9c1e116cf349…
- git.kernel.org/stable/c/de02fc049352af5a95…
- git.kernel.org/stable/c/fd238c51b0fa5390cc…