CVE-2026-63994

Summary

In the Linux kernel, the following vulnerability has been resolved:

tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmpv6

Sashiko found that iptunnel_pmtud_build_icmp() and iptunnel_pmtud_build_icmpv6() were caching ip_hdr() and ipv6_hdr() before an skb_cow() call which can reallocate skb->head.

Fix this possible UAF by initializing the local variables after the skb_cow() call.

Remove skb_reset_network_header() calls which were not needed.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 95b6d772bfe788331d9742d73eaa12e113b2adc4affected
LinuxLinux4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 7254aef4d1a7e18e887af9010e2f2dc34806789baffected
LinuxLinux4cb47a8644cc9eb8ec81190a50e79e6530d0297f < bf8b3f34c37c162357138e7c0942723b8b94fed1affected
LinuxLinux4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 76cd9398a0470257ab765bdf5f358a2af2e17934affected
LinuxLinux4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 50750d86a2e5266aba0c295483b3397843198b11affected
LinuxLinux4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 6dff77899b9e9fe5d854abda3a98ad04e7229ef7affected
LinuxLinux4cb47a8644cc9eb8ec81190a50e79e6530d0297f < f3f204541f280a6ecb04503a0d6794d93990ca43affected
LinuxLinux4cb47a8644cc9eb8ec81190a50e79e6530d0297f < b4bc94353050b1fa7b702bd4c6600710dd926cffaffected
LinuxLinux5.9affected
LinuxLinux0 < 5.9unaffected
LinuxLinux5.10.259 <= 5.10.*unaffected
LinuxLinux5.15.210 <= 5.15.*unaffected
LinuxLinux6.1.176 <= 6.1.*unaffected
LinuxLinux6.6.143 <= 6.6.*unaffected
LinuxLinux6.12.93 <= 6.12.*unaffected
LinuxLinux6.18.35 <= 6.18.*unaffected
LinuxLinux7.0.12 <= 7.0.*unaffected
LinuxLinux7.1 <= *unaffected

Weaknesses

References