Description
In the Linux kernel, the following vulnerability has been resolved:

vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()

skb_tunnel_check_pmtu() can change skb->head.

Reusing old_iph afer skb_tunnel_check_pmtu() can cause an UAF.

Use instead ip_hdr(skb) as done in drivers/net/bareudp.c
and drivers/net/geneve.c.

Found by Sashiko.
Published: 2026-07-19
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in Linux kernel VXLAN code that can lead to memory corruption and arbitrary code execution
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, vxlan processing code caches an IP header pointer, which can be invalidated when the packet buffer is altered by skb_tunnel_check_pmtu(). Reusing the stale pointer results in a use‑after‑free (CWE‑416, CWE‑825). The memory corruption can crash the system or, if attacker controls the freed region, enable arbitrary code execution.

Affected Systems

All Linux kernel builds that include VXLAN support are affected. The CPE list mentions kernels 7.1rc1 through 7.1rc5 as examples, indicating that any kernel with VXLAN enabled, including current mainstream releases, is at risk.

Risk and Exploitability

The CVSS score of 9.8 highlights severe impact, while the EPSS score of less than 1% suggests the exploitation probability is currently low. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need to send a crafted VXLAN packet to a host that has an active VXLAN interface; thus the attack surface is limited to systems with VXLAN enabled.

Generated by OpenCVE AI on October 2, 2026 at 22:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version containing the commit that replaces the cached ip_hdr() reference with a fresh ip_hdr(skb) call.
  • If a kernel upgrade cannot be performed, disable VXLAN interfaces or block VXLAN traffic with firewall rules to restrict acceptance to trusted sources.
  • Ensure any third‑party or supplemental VXLAN modules are replaced with versions that include the fix.

Generated by OpenCVE AI on October 2, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8593-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8603-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8618-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8663-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8664-1 Linux kernel (NVIDIA BaseOS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8728-1 Linux kernel (GCP) vulnerabilities
Ubuntu USN Ubuntu USN USN-8781-1 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8728-2 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8817-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8818-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8818-2 Linux kernel (IBM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8728-3 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8842-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8818-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8818-4 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8849-1 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8817-3 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8818-5 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8871-1 Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu USN Ubuntu USN USN-8878-1 Linux kernel (GCP) vulnerabilities
Ubuntu USN Ubuntu USN USN-8879-1 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8906-1 Linux kernel (IBM) vulnerabilities
History

Fri, 02 Oct 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CPEs cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*

Wed, 22 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Mon, 20 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sun, 19 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() skb_tunnel_check_pmtu() can change skb->head. Reusing old_iph afer skb_tunnel_check_pmtu() can cause an UAF. Use instead ip_hdr(skb) as done in drivers/net/bareudp.c and drivers/net/geneve.c. Found by Sashiko.
Title vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-05T12:37:57.287Z

Reserved: 2026-07-19T07:54:57.025Z

Link: CVE-2026-63993

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-19T16:17:38.823

Modified: 2026-10-02T19:57:14.137

Link: CVE-2026-63993

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-19T00:00:00Z

Links: CVE-2026-63993 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T22:45:18Z

Weaknesses