CVE-2026-63992
The Linux kernel contains a flaw in its tunnel handling code where the function iptunnel_pmtud_check_icmp() can be invoked before the socket buffer's transport header is set, causing an out-of-bounds memory access. The issue has been fixed by accessing the ICMP header based on the IPv4 network header after verifying its presence. No public exploit or known active exploitation is reported.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users
Real-world impact
An attacker could trigger an out-of-bounds read/write, potentially leading to information disclosure or denial of service.
Why this severity
CVSS v3.1 base score 9.1 (Critical) due to network attack vector, low complexity, no privileges or user interaction required, high confidentiality and availability impacts.
What to do about it
- 01Update the Linux kernel to a version that includes the patch for CVE-2026-63992.
NVD-referenced vendor advisory (Linux kernel fix)
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/43368636c663cff6e5…
- git.kernel.org/stable/c/509323077ef79a26ba…
- git.kernel.org/stable/c/5a92cb45e34749865d…
- git.kernel.org/stable/c/7f4f7efe7f30edd29c…
- git.kernel.org/stable/c/a096b6e34f602950af…
- git.kernel.org/stable/c/c7b7ec3e69e673c0d6…
- git.kernel.org/stable/c/cb549df9ce4ee15c9d…
- git.kernel.org/stable/c/e917d0c69f01af2bb4…