{"id":"CVE-2026-63992","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ntunnels: do not assume transport header in iptunnel_pmtud_check_icmp()\n\nIn some cases, iptunnel_pmtud_check_icmp() can be called while\nskb transport header is not set.\n…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ntunnels: do not assume transport header in iptunnel_pmtud_check_icmp()\n\nIn some cases, iptunnel_pmtud_check_icmp() can be called while\nskb transport header is not set.\n…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","cwe":["CWE-125"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 5.9, < 5.10.259","linux_kernel >= 5.11, < 5.15.210","linux_kernel >= 5.16, < 6.1.176","linux_kernel >= 6.2, < 6.6.143","linux_kernel >= 6.7, < 6.12.93","linux_kernel >= 6.13, < 6.18.35","linux_kernel >= 6.19, < 7.0.12","linux_kernel = 7.1"],"patched":["linux_kernel 7.0.12"],"published":"2026-07-19","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:29:43.487","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63992","references":[{"url":"https://git.kernel.org/stable/c/43368636c663cff6e59dde93cf4b8e43ac28eb93","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/509323077ef79a26ba0c60bb556e45c12c398b2d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a92cb45e34749865d03daf8d3500f77b5f6644c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f4f7efe7f30edd29c4988de01728bf2398217e4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a096b6e34f602950af9a2b0856cd93a5f4c276d7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7b7ec3e69e673c0d6b57f74d21da50c485c598e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb549df9ce4ee15c9d5b19ddab12cf2128e4313c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e917d0c69f01af2bb4fbea2b66d560a53b3ac7ec","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00514,"epssPercentile":0.41838,"ingestedAt":"2026-10-07T20:46:46.957Z","slug":"CVE-2026-63992","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ntunnels: do not assume transport header in iptunnel_pmtud_check_icmp()\n\nIn some cases, iptunnel_pmtud_check_icmp() can be called while\nskb transport header is not set.\n\nThis triggers an out-of-bound access, because\n(typeof(skb->transport_header))~0U is 65535.\n\nAccess the icmp header based on IPv4 network header,\nafter making sure icmp->type is present in skb linear part.\n\nNote that iptunnel_pmtud_check_icmpv6()) is fine.\n\n## Affected\n\n- `linux_kernel >= 5.9, < 5.10.259`\n- `linux_kernel >= 5.11, < 5.15.210`\n- `linux_kernel >= 5.16, < 6.1.176`\n- `linux_kernel >= 6.2, < 6.6.143`\n- `linux_kernel >= 6.7, < 6.12.93`\n- `linux_kernel >= 6.13, < 6.18.35`\n- `linux_kernel >= 6.19, < 7.0.12`\n- `linux_kernel = 7.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 7.0.12`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}