CVE-2026-63991
Published Jul 19, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() The skb_clone() function can return NULL if memory allocation fails. send_mcast_pkt() calls skb_clone() without checking the return value, which can lead to a NULL pointer dereference in send_pkt() when it dereferences skb->data. Add a NULL check after skb_clone() and skip the peer if the clone fails.
Is your site exposed to CVE-2026-63991?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/2061d080a013c0ec0a56162cd501fb36d2befc26
https://git.kernel.org/stable/c/3c40d381ce04f9575a5d8b542898183c3b4b38dc
https://git.kernel.org/stable/c/3d5d81d294ba09487c86bc4ba33dc4a4bec5d215
https://git.kernel.org/stable/c/9903a04becf059e44cccf625e23689b7d4378384
https://git.kernel.org/stable/c/9afcb5ea080af13aab37930da627db43bd277665
https://git.kernel.org/stable/c/b06203ac5f12929d79146bb9f063c2af1d679e63
https://git.kernel.org/stable/c/d630c4b25f36e0e68461561e4c70957ec37fdedd
https://git.kernel.org/stable/c/e673889a35a5e4c586d0fae67d8755ca4367d3e2
Frequently Asked Questions
What is CVE-2026-63991? +
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()
The skb_clone() function can return NULL if memory allocation fails.
send_mcast_pkt() calls skb_clone() without checking the return value, which
can lead to a NULL pointer dereference in send_pkt() when it dereferences
skb->data.
Add a NULL check after skb_clone() and skip the peer if the clone fails.
How do I check if I'm vulnerable to CVE-2026-63991? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.