Junglewise Threat Intelligence

CVE-2026-63984: Linux Kernel integer overflow in IPv6 RPL Source Routing Header decompression

CVE-2026-63984 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's IPv6 implementation could allow network traffic to corrupt system memory. The issue occurs when processing specific types of routing headers used in low-power and lossy networks (RPL). An attacker could potentially cause a system crash or interfere with network operations by sending specially crafted packets that trigger an internal calculation error.

Technical details

An integer overflow exists in the `ipv6_rpl_srh_decompress()` function within `net/ipv6/exthdrs.c`. The function calculates the output header length (`hdrlen`) using the formula `(((n + 1) * sizeof(struct in6_addr)) >> 3)`. Because `hdrlen` is an 8-bit unsigned integer (`__u8`), values of `n >= 127` result in a value exceeding 255, causing a silent truncation. This leads to an incorrect buffer offset in `ipv6_rpl_srh_rcv()`, causing the compressed header to overlap and corrupt the decompressed routing data. The fix tightens the validation bound for `n` from 255 to 127 to ensure the calculated length always fits within the 8-bit field.

Affected products

  • Linux Linux Kernel 8610c7c6e3bd to 75b3680047bf, fd238c51b0fa, 3618b34942b7, 97e06791368c, de02fc049352, c0487a9c1e11, 6fe1cb312038, 9d5e7a46a9f6

Timeline

  • 2026-05-25: disclosed: Initial patch submission by Rahul Chandelkar
  • 2026-06-19: patched: Patch committed to stable branches by Greg Kroah-Hartman
  • 2026-07-19: advisory: CVE published in NVD dataset

References

Related threats