Widespread Linux kernel bug in tunnel ICMP handling; impacts many distributions and networked systems, likely to disrupt servers and infrastructure if exploited.
CVE-2026-63992
Linux kernel tunnel ICMP handling OOB access can crash kernel or enable escalation.
Is CVE-2026-63992 being exploited?
Not confirmed. CVE-2026-63992 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.51% probability of exploitation in the next 30 days.
How severe is CVE-2026-63992?
CVE-2026-63992 is rated Critical with a CVSS score of 9.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63992?
Yes. A fix has been recorded for CVE-2026-63992. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63992 affect?
CVE-2026-63992 affects Linux kernel (iptunnel/iptunnel_pmtud_check_icmp), Linux distributions using affected kernels (Ubuntu/Debian/RHEL/SUSE/etc.), Network appliances using upstream Linux kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63992?
Apply vendor kernel patches immediately and reboot affected hosts; update network appliances.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Crafted ICMP in IP tunnels can trigger out-of-bounds access causing kernel crash (DoS) and potentially enable privilege escalation or RCE.
Immediate action required
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < 5a92cb45e34749865d03daf8d3500f77b5f6644c
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < c7b7ec3e69e673c0d6b57f74d21da50c485c598e
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < 7f4f7efe7f30edd29c4988de01728bf2398217e4
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < e917d0c69f01af2bb4fbea2b66d560a53b3ac7ec
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < a096b6e34f602950af9a2b0856cd93a5f4c276d7
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < 43368636c663cff6e59dde93cf4b8e43ac28eb93
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < cb549df9ce4ee15c9d5b19ddab12cf2128e4313c
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < 509323077ef79a26ba0c60bb556e45c12c398b2d
- affected5.9
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.