CVE-2026-63993
Published Jul 19, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() skb_tunnel_check_pmtu() can change skb->head. Reusing old_iph afer skb_tunnel_check_pmtu() can cause an UAF. Use instead ip_hdr(skb) as done in drivers/net/bareudp.c and drivers/net/geneve.c. Found by Sashiko.
Is your site exposed to CVE-2026-63993?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/5303925e360527243b46a440a04667826bbc72b7
https://git.kernel.org/stable/c/609e63312c29aad18026a1d3222e123d4b6b0feb
https://git.kernel.org/stable/c/6b8bfce9d2f774d2c2243e0248e03efb99bba6c0
https://git.kernel.org/stable/c/7d9ef0cb271555d8cf39fefe6c981e1493b25ecf
https://git.kernel.org/stable/c/8d435d68d71fb875876b722f4136caf74f2f48bd
https://git.kernel.org/stable/c/9257f56ac47ef1976bcd056cf986a9988eeec67a
https://git.kernel.org/stable/c/a493efd4336cf19122ae0e4cbb3d31b32d70deea
https://git.kernel.org/stable/c/dc3bfa050f873371e745bdf478b1f5b738e5733d
Frequently Asked Questions
What is CVE-2026-63993? +
In the Linux kernel, the following vulnerability has been resolved:
vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
skb_tunnel_check_pmtu() can change skb->head.
Reusing old_iph afer skb_tunnel_check_pmtu() can cause an UAF.
Use instead ip_hdr(skb) as done in drivers/net/bareudp.c
and drivers/net/geneve.c.
Found by Sashiko.
How do I check if I'm vulnerable to CVE-2026-63993? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.