CVE-2026-63922

critical

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_network_header(skb) in nh while walking IPv6 TLVs. ipv6_dest_hao() may call pskb_expand_head() for a cloned skb, which can move the skb head and invalidate the cached network header pointer. Refresh nh after ipv6_dest_hao() returns so any trailing padding or TLVs are parsed from the current skb head. This matches the existing pattern used in ip6_parse_tlv() after helpers that can modify skb header storage.

References

https://git.kernel.org/stable/c/ff375ed1cba81392346c5bfbf0bb7a13b2946f99

https://git.kernel.org/stable/c/f8aabed3ff3e986920cf02a2a2785e08e586b234

https://git.kernel.org/stable/c/f7b52afe3592eae66e160586b45a3f2242972c63

https://git.kernel.org/stable/c/9b6dcc0a39fd71752937f0b6b3973e1416085dcf

https://git.kernel.org/stable/c/751db1b802a067b7fff25880f4e9f9152a171538

https://git.kernel.org/stable/c/1a11eb7431e3d2882f5bd5939c5a9bbc65ccf4d1

https://git.kernel.org/stable/c/12d957979e4a800167842f1b42be6a606d227ebe

Details

Source: Mitre, NVD

Published: 2026-07-19

Updated: 2026-07-20

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00205