Linux kernel vulnerability affecting GCOV-instrumented builds and IPComp processing; widespread kernel impact with potential DoS/RCE risk that merits broad attention.
CVE-2026-63825
Kernel GCOV race causes OOB write in inflate_fast via IPComp; crash/RCE risk.
Is CVE-2026-63825 being exploited?
Not confirmed. CVE-2026-63825 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.78% probability of exploitation in the next 30 days.
How severe is CVE-2026-63825?
CVE-2026-63825 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63825?
Yes. A fix has been recorded for CVE-2026-63825. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63825 affect?
CVE-2026-63825 affects Linux kernel (GCOV-instrumented builds), xfrm_ipcomp / IPComp processing, Systems handling IPComp-compressed network traffic, Distributions with gcov enabled in kernel builds. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63825?
Apply vendor kernel updates immediately; disable IPComp or avoid GCOV-enabled kernels until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Out-of-bounds kernel write in inflate_fast during IPComp processing; can cause kernel panic (DoS) and may enable privilege escalation or remote code execution via crafted packets.
Immediate action required
- affected>= 2521f2c228ad750701ba4702484e31d876dbc386 and < 49d893b9cbcfc5802a32e53a64c6c6956670d65b
- affected>= 2521f2c228ad750701ba4702484e31d876dbc386 and < 5b959c1dbb4522b9e3ac4e26ad638b8784869841
- affected>= 2521f2c228ad750701ba4702484e31d876dbc386 and < 56cb9b7d96b28a1173a510ab25354b6599ad3a33
- affected2.6.31
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.