Junglewise Threat Intelligence

CVE-2026-63924: Linux Kernel pointer invalidation in IPv6 extension header handling

CVE-2026-63924 · Severity: info · CVSS 5.3 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's IPv6 networking component could lead to system instability. When processing specific large network packets (Jumbograms), the system may use outdated memory references, potentially causing a crash or unpredictable behavior. This affects the reliability of servers and devices using IPv6.

Technical details

A vulnerability exists in net/ipv6/exthdrs.c within the Linux kernel. The function ipv6_hop_jumbo() calls pskb_trim_rcsum(), which may reallocate or shift the socket buffer (skb), effectively invalidating existing pointers to the network header (nh). If the nh pointer is not refreshed after this call, subsequent kernel operations may perform invalid memory accesses. An attacker could potentially trigger this by sending specially crafted IPv6 Hop-by-Hop options containing Jumbo Payload TLVs. The fix involves recomputing the nh pointer using skb_network_header(skb) immediately after the jumbo packet processing.

Affected products

  • Linux Linux Kernel 2.6.12 to 6.10.y

Timeline

  • 2026-05-22: disclosed: Initial patch submitted by Justin Iurman
  • 2026-06-09: patched: Patch merged into various stable branches
  • 2026-07-19: advisory: CVE-2026-63924 published by NVD

References

Related threats