Junglewise Threat Intelligence

CVE-2026-63981: Linux Kernel stack overflow in act_mirred blockcast recursion

CVE-2026-63981 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to crash the system. The issue occurs when specific network traffic redirection rules (mirred blockcast) are configured in a way that creates an infinite loop, exhausting the system's memory stack. This results in a kernel panic, leading to a complete system outage or denial of service.

Technical details

A stack overflow vulnerability exists in net/sched/act_mirred.c due to a logic error in recursion limiting. The function tcf_mirred_act() implements a nesting limit (MIRRED_NEST_LIMIT) to prevent infinite loops; however, when the 'blockcast' action is used, the function returns before the recursion counter is incremented. An attacker with CAP_NET_ADMIN privileges (which can be obtained by unprivileged users via user and network namespaces) can configure shared TC egress blocks to trigger an infinite loop between devices. This results in a kernel panic when the task stack guard page is hit. The fix involves moving the counter increment before the blockcast call.

Affected products

  • Linux Linux Kernel 906736728cea480a85803c67fafb1b0e78491922 to 25fc9352590f5ef21ebf290432bd768b336693bc, fe946a751d9b52b7c45ca34899723b314b79b249 to 34457de389fb64a01fdcc71177dfebe65fd2d362, fe946a751d9b52b7c45ca34899723b314b79b249 to a005fa5d7502eefec7ee6e1c01adadc06de2f9ad

Timeline

  • 2026-05-25: other: Patch authored
  • 2026-07-19: disclosed: CVE published

References

Related threats