Skip to content
CVSS 9.1 · CRITICAL

CVE-2026-63992

In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() In some cases, iptunnel_pmtud_check_icmp() can be called while skb transport header is not set. This triggers an out-of-bound access, because (typeof(skb->transport_header))~0U is 65535. Access the icmp header based on IPv4 network header, after making sure icmp->type is present in skb linear part. Note that iptunnel_pmtud_check_icmpv6()) is fine.

View on NVD

Analysis

A critical vulnerability was discovered in the Linux kernel's IP tunneling code. This issue allows for out-of-bounds memory access when processing certain ICMP packets, which can lead to system instability or potential remote exploitation on systems acting as tunnel endpoints.

Relevant roles

LinuxCyberSecurityBackendCloudDockerKubernetes

Severity

Score: 9.1(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: NONE
A: HIGH

EPSS

Probability of exploitation (next 30 days): 0.0018 (0.2%)
Percentile: 7.4%
EPSS: 2026-07-20

Technical description

In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() In some cases, iptunnel_pmtud_check_icmp() can be called while skb transport header is not set. This triggers an out-of-bound access, because (typeof(skb->transport_header))~0U is 65535. Access the icmp header based on IPv4 network header, after making sure icmp->type is present in skb linear part. Note that iptunnel_pmtud_check_icmpv6()) is fine.

Published: 7/19/2026, 4:17:38 PM
Last modified: 7/20/2026, 3:17:00 PM

References

HomeEventsBlogResourcesTeam