Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-63922

In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_network_header(skb) in nh while walking IPv6 TLVs. ipv6_dest_hao() may call pskb_expand_head() for a cloned skb, which can move the skb head and invalidate the cached network header pointer. Refresh nh after ipv6_dest_hao() returns so any trailing padding or TLVs are parsed from the current skb head. This matches the existing pattern used in ip6_parse_tlv() after helpers that can modify skb header storage.

View on NVD

Analysis

A critical vulnerability (CVSS 9.8) has been identified in the Linux kernel networking stack. The flaw in IPv6 extension header parsing could lead to memory corruption when processing specific packets, potentially allowing for remote exploitation or system instability. Users should prioritize kernel updates across Linux-based servers and container hosts.

Relevant roles

LinuxDockerKubernetesBackendCloudCyberSecurity

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH

EPSS

Probability of exploitation (next 30 days): 0.0021 (0.2%)
Percentile: 10.7%
EPSS: 2026-07-20

Technical description

In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_network_header(skb) in nh while walking IPv6 TLVs. ipv6_dest_hao() may call pskb_expand_head() for a cloned skb, which can move the skb head and invalidate the cached network header pointer. Refresh nh after ipv6_dest_hao() returns so any trailing padding or TLVs are parsed from the current skb head. This matches the existing pattern used in ip6_parse_tlv() after helpers that can modify skb header storage.

Published: 7/19/2026, 4:17:10 PM
Last modified: 7/20/2026, 3:16:56 PM

References

HomeEventsBlogResourcesTeam