CVE-2026-63922
Published Jul 19, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_network_header(skb) in nh while walking IPv6 TLVs. ipv6_dest_hao() may call pskb_expand_head() for a cloned skb, which can move the skb head and invalidate the cached network header pointer. Refresh nh after ipv6_dest_hao() returns so any trailing padding or TLVs are parsed from the current skb head. This matches the existing pattern used in ip6_parse_tlv() after helpers that can modify skb header storage.
Is your site exposed to CVE-2026-63922?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/12d957979e4a800167842f1b42be6a606d227ebe
https://git.kernel.org/stable/c/1a11eb7431e3d2882f5bd5939c5a9bbc65ccf4d1
https://git.kernel.org/stable/c/751db1b802a067b7fff25880f4e9f9152a171538
https://git.kernel.org/stable/c/9b6dcc0a39fd71752937f0b6b3973e1416085dcf
https://git.kernel.org/stable/c/f7b52afe3592eae66e160586b45a3f2242972c63
https://git.kernel.org/stable/c/f8aabed3ff3e986920cf02a2a2785e08e586b234
https://git.kernel.org/stable/c/ff375ed1cba81392346c5bfbf0bb7a13b2946f99
Frequently Asked Questions
What is CVE-2026-63922? +
In the Linux kernel, the following vulnerability has been resolved:
ipv6: exthdrs: refresh nh after handling HAO option
ip6_parse_tlv() caches skb_network_header(skb) in nh while walking
IPv6 TLVs.
ipv6_dest_hao() may call pskb_expand_head() for a cloned skb, which can
move the skb head and invalidate the cached network header pointer.
Refresh nh after ipv6_dest_hao() returns so any trailing padding or TLVs
are parsed from the current skb head.
This matches the existing pattern used in ip6_parse_tlv() after helpers
that can modify skb header storage.
How do I check if I'm vulnerable to CVE-2026-63922? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.