PT-2026-61301 · Linux+1 · Linux Kernel+1
CVE-2026-63984
·
Published
2026-07-19
·
Updated
2026-09-09
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An integer overflow occurs in the
ipv6 rpl srh decompress() function when processing Routing Header (SRH) decompression. The hdrlen variable, defined as u8, fails to hold values when n is 127 or greater, causing the result to be silently truncated. This leads to a memory overlap where the compressed header is placed at an incorrect offset, allowing ipv6 rpl srh compress() to overwrite and corrupt the routing header of the forwarded packet.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Ubuntu