Review reviewCritical

CVE-2026-63994

Linux

In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() Sashiko found that iptunnel_pmtud_build_icmp() and iptunnel_pmtud_build_icmpv6() were caching ip_hdr() and ipv6_hdr() before an skb_cow() call which can reallocate skb->head. Fix this possible UAF by initializing the local variables after the skb_cow() call. Remove skb_reset_network_header() calls which were not needed.

CVSS
9.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 9.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() Sashiko found that iptunnel_pmtud_build_icmp() and iptunnel_pmtud_build_icmpv6() were caching ip_hdr() and ipv6_hdr() before an skb_cow() call which can reallocate skb->head. Fix this possible UAF by initializing the local variables after the skb_cow() call. Remove skb_reset_network_header() calls which were not needed.

Affected product and versions

Product
Linux
Affected versions
>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 95b6d772bfe788331d9742d73eaa12e113b2adc4, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 7254aef4d1a7e18e887af9010e2f2dc34806789b, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < bf8b3f34c37c162357138e7c0942723b8b94fed1, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 76cd9398a0470257ab765bdf5f358a2af2e17934, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 50750d86a2e5266aba0c295483b3397843198b11, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 6dff77899b9e9fe5d854abda3a98ad04e7229ef7, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < f3f204541f280a6ecb04503a0d6794d93990ca43, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < b4bc94353050b1fa7b702bd4c6600710dd926cff, >= 5.9
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2026-63994 — Linux | SECUFOCUS NOW