Description
In the Linux kernel, the following vulnerability has been resolved:

tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()

In some cases, iptunnel_pmtud_check_icmp() can be called while
skb transport header is not set.

This triggers an out-of-bound access, because
(typeof(skb->transport_header))~0U is 65535.

Access the icmp header based on IPv4 network header,
after making sure icmp->type is present in skb linear part.

Note that iptunnel_pmtud_check_icmpv6()) is fine.
Published: 2026-07-19
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds Read
Action: Apply Patch
AI Analysis

Impact

The issue occurs when the function that checks for Path MTU Discovery on IP tunnels is invoked while the socket buffer’s transport header has not yet been initialized. In that condition the function treats the uninitialized transport header as an offset, which resolves to the maximum unsigned value of a 16‑bit number. As a result, the code attempts to read beyond the end of the packet’s data, resulting in an out‑of‑bounds read of the ICMP header. The applied fix removes the assumption that the transport header is set and adds a bounds check by accessing the ICMP header based on the IPv4 network header and ensuring it lies within the linear part of the packet.

Affected Systems

Every Linux kernel build that still contains the original iptunnel_pmtud_check_icmp() logic is affected. The CPE list includes the generic Linux kernel as well as the 7.1 release candidates from rc1 through rc5. Distributions shipping any of those upstream kernels without the referenced commits are at risk until they update to a kernel that incorporates the fix.

Risk and Exploitability

The CVSS score of 9.1 points to a high‑impact vulnerability, yet the EPSS score is below 1%, indicating that exploitation attempts are very rare. The vulnerability is not part of the CISA KEV catalog. The likely attack vector is remote network delivery of specially crafted ICMP packets, inferred because the vulnerability is triggered by incoming packets processed by iptunnel_pmtud_check_icmp() on tunnel interfaces. By doing so, an attacker could read kernel memory contents, potentially leaking sensitive data. The attack does not require local privileges; it is limited to information disclosure rather than a crash or denial of service.

Generated by OpenCVE AI on October 7, 2026 at 23:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that fixes the out-of-bounds read (CWE-125) and the bounds checking flaw (CWE-805) within iptunnel_pmtud_check_icmp()
  • Reboot the system to load the patched kernel
  • If an immediate kernel upgrade is not possible, block or rate‑limit ICMP traffic that could trigger MTU discovery on tunnel interfaces

Generated by OpenCVE AI on October 7, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8593-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8603-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8618-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8663-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8664-1 Linux kernel (NVIDIA BaseOS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8728-1 Linux kernel (GCP) vulnerabilities
Ubuntu USN Ubuntu USN USN-8781-1 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8728-2 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8817-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8818-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8818-2 Linux kernel (IBM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8728-3 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8842-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8818-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8818-4 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8849-1 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8817-3 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8818-5 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8871-1 Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu USN Ubuntu USN USN-8878-1 Linux kernel (GCP) vulnerabilities
Ubuntu USN Ubuntu USN USN-8879-1 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8906-1 Linux kernel (IBM) vulnerabilities
History

Wed, 07 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CPEs cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*

Wed, 22 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-805
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 20 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Sun, 19 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() In some cases, iptunnel_pmtud_check_icmp() can be called while skb transport header is not set. This triggers an out-of-bound access, because (typeof(skb->transport_header))~0U is 65535. Access the icmp header based on IPv4 network header, after making sure icmp->type is present in skb linear part. Note that iptunnel_pmtud_check_icmpv6()) is fine.
Title tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-05T12:37:55.661Z

Reserved: 2026-07-19T07:54:57.025Z

Link: CVE-2026-63992

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-19T16:17:38.700

Modified: 2026-10-07T20:29:43.487

Link: CVE-2026-63992

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-19T00:00:00Z

Links: CVE-2026-63992 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:45:15Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-805

    Buffer Access with Incorrect Length Value