CVE-2026-63922

Summary

In the Linux kernel, the following vulnerability has been resolved:

ipv6: exthdrs: refresh nh after handling HAO option

ip6_parse_tlv() caches skb_network_header(skb) in nh while walking IPv6 TLVs.

ipv6_dest_hao() may call pskb_expand_head() for a cloned skb, which can move the skb head and invalidate the cached network header pointer. Refresh nh after ipv6_dest_hao() returns so any trailing padding or TLVs are parsed from the current skb head.

This matches the existing pattern used in ip6_parse_tlv() after helpers that can modify skb header storage.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxa831f5bbc89a9978795504be9e1ff412043f8f77 < f8aabed3ff3e986920cf02a2a2785e08e586b234affected
LinuxLinuxa831f5bbc89a9978795504be9e1ff412043f8f77 < 1a11eb7431e3d2882f5bd5939c5a9bbc65ccf4d1affected
LinuxLinuxa831f5bbc89a9978795504be9e1ff412043f8f77 < 12d957979e4a800167842f1b42be6a606d227ebeaffected
LinuxLinuxa831f5bbc89a9978795504be9e1ff412043f8f77 < ff375ed1cba81392346c5bfbf0bb7a13b2946f99affected
LinuxLinuxa831f5bbc89a9978795504be9e1ff412043f8f77 < 751db1b802a067b7fff25880f4e9f9152a171538affected
LinuxLinuxa831f5bbc89a9978795504be9e1ff412043f8f77 < 9b6dcc0a39fd71752937f0b6b3973e1416085dcfaffected
LinuxLinuxa831f5bbc89a9978795504be9e1ff412043f8f77 < f7b52afe3592eae66e160586b45a3f2242972c63affected
LinuxLinux2.6.19affected
LinuxLinux0 < 2.6.19unaffected
LinuxLinux5.15.210 <= 5.15.*unaffected
LinuxLinux6.1.176 <= 6.1.*unaffected
LinuxLinux6.6.143 <= 6.6.*unaffected
LinuxLinux6.12.93 <= 6.12.*unaffected
LinuxLinux6.18.35 <= 6.18.*unaffected
LinuxLinux7.0.12 <= 7.0.*unaffected
LinuxLinux7.1 <= *unaffected

Weaknesses

References