Review reviewCritical

CVE-2026-63912

Linux

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer in esp_output_head() before esp_output_tail() allocates the destination page frag. The head-side gate currently checks skb->data_len and tailen separately, but the tail code allocates a single destination frag from the combined post-trailer skb->data_len. Reject the page-frag fast path when the combined aligned length exceeds a page. Otherwise skb_page_frag_refill() may fall back to a single page while the destination sg s...

CVSS
9.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 9.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer in esp_output_head() before esp_output_tail() allocates the destination page frag. The head-side gate currently checks skb->data_len and tailen separately, but the tail code allocates a single destination frag from the combined post-trailer skb->data_len. Reject the page-frag fast path when the combined aligned length exceeds a page. Otherwise skb_page_frag_refill() may fall back to a single page while the destination sg s...

Affected product and versions

Product
Linux
Affected versions
>= c075c3ea031757f8ea2d34567565b61a868c08d5 < 566295735530ee513326049b0540f32ec050bf2e, >= a583f2f3c8788bffd7fd7baeb76bd6d80543d7ea < 5d7ab86e2b6bc23054616bf6ac562013bf60af8c, >= 5bd8baab087dff657e05387aee802e70304cc813 < 36519e3d941fc99d3b52c134dbaf311f987a4708, >= 5bd8baab087dff657e05387aee802e70304cc813 < 322e48187e0245ab2fff6fec2220b0cae677dbec, >= 5bd8baab087dff657e05387aee802e70304cc813 < b84091ceddc9f133229dceab3ccc930bf27f9cba, >= 5bd8baab087dff657e05387aee802e70304cc813 < c093468aea8277f77272a4f199b2e15e19cabb59, >= 5bd8baab087dff657e05387aee802e70304cc813 < 65f3b3fc2347b89fe21db1e92c7681368415f095, >= 5bd8baab087dff657e05387aee802e70304cc813 < dfa0d7b0ff1eb6b2c416b8fdb9b4f2cefba57a40, >= 2c66b0c95bb0aa7652ba1eba293d0d5993b35a38, >= ef6f83df1209a7d9bd1c605a62457d4c00f9179e, >= 3defefd22ad5fbbe639b6157fb7e6311b2bf333d, >= b657030870bb5351c5b1e84d4e9f186da6ca0496, >= 5.10.113 < 5.10.259, >= 5.15.36 < 5.15.210, >= 4.14.288 < 4.15, >= 4.19.252 < 4.20, >= 5.4.205 < 5.5, >= 5.17.5 < 5.18, >= 5.18
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2026-63912 — Linux | SECUFOCUS NOW