CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-63922

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
0.68%
49th pct
KEV
No
Class
oss containerizable

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_network_header(skb) in nh while walking IPv6 TLVs. ipv6_dest_hao() may call pskb_expand_head() for a cloned skb, which can move the skb head and invalidate the cached network header pointer. Refresh nh after ipv6_dest_hao() returns so any trailing padding or TLVs are parsed from the current skb head. This matches the existing pattern used in ip6_parse_tlv() after helpers that can modify skb header storage.

Affected packages

Linux Kernel 2.6.19 → 5.15.210
Linux Kernel 5.16.0 → 6.1.176
Linux Kernel 6.13.0 → 6.18.35
Linux Kernel 6.19.0 → 7.0.12
Linux Kernel 6.2.0 → 6.6.143
Linux Kernel 6.7.0 → 6.12.93

References

Status: profiled · ingested 2026-07-20T18:00:18.000Z