Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-63993

39
FAUCET Score

In the Linux kernel, the following vulnerability has been resolved: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() skb_tunnel_check_pmtu() can change skb->head. Reusing old_iph afer skb_tunnel_check_pmtu() can cause an UAF. Use instead ip_hdr(skb) as done in drivers/net/bareudp.c and drivers/net/geneve.c. Found by Sashiko.

First published: Jul 19, 2026Last modified: Jul 20, 2026

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
5.9CNA affecteddefault affected
LinuxLinux
>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < 5303925e360527243b46a440a04667826bbc72b7, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < 609e63312c29aad18026a1d3222e123d4b6b0feb, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < 6b8bfce9d2f774d2c2243e0248e03efb99bba6c0, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < 7d9ef0cb271555d8cf39fefe6c981e1493b25ecf, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < 8d435d68d71fb875876b722f4136caf74f2f48bd, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < 9257f56ac47ef1976bcd056cf986a9988eeec67a, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < a493efd4336cf19122ae0e4cbb3d31b32d70deea, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f, < dc3bfa050f873371e745bdf478b1f5b738e5733dCNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.51%
Probability of exploitation in next 30 days
EPSS Percentile
40.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0051 is in the 20th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (resolute)Fixed in: 7.0.0-1010.10
ubuntupatch availablevia ubuntu_usn
Product: linux-oracle (resolute)Fixed in: 7.0.0-1008.8
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (resolute)Fixed in: 7.0.0-1010.10
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fde (resolute)Fixed in: 7.0.0-1009.9

Vendor Advisories (2)

ubuntuUSN-8603-1

Linux kernel (Azure) vulnerabilities

Jul 24, 2026
ubuntuUSN-8593-1

Linux kernel vulnerabilities

Jul 23, 2026

References

git.kernel.org / stable/c/5303925e360527243b46a440a04667826bbc72b7
git.kernel.org / stable/c/609e63312c29aad18026a1d3222e123d4b6b0feb
git.kernel.org / stable/c/6b8bfce9d2f774d2c2243e0248e03efb99bba6c0
git.kernel.org / stable/c/7d9ef0cb271555d8cf39fefe6c981e1493b25ecf
git.kernel.org / stable/c/8d435d68d71fb875876b722f4136caf74f2f48bd
git.kernel.org / stable/c/9257f56ac47ef1976bcd056cf986a9988eeec67a
git.kernel.org / stable/c/a493efd4336cf19122ae0e4cbb3d31b32d70deea
git.kernel.org / stable/c/dc3bfa050f873371e745bdf478b1f5b738e5733d