Critical Linux kernel vxlan UAF affecting widely deployed kernels; can enable kernel compromise and infrastructure disruption.
CVE-2026-63993
Linux kernel VXLAN use-after-free allows kernel memory corruption and potential compromise.
Is CVE-2026-63993 being exploited?
Not confirmed. CVE-2026-63993 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.51% probability of exploitation in the next 30 days.
How severe is CVE-2026-63993?
CVE-2026-63993 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63993?
Yes. A fix has been recorded for CVE-2026-63993. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63993 affect?
CVE-2026-63993 affects Linux kernel (vxlan subsystem), Major Linux distros (Ubuntu, Debian, RHEL, CentOS, SUSE), Cloud VMs running affected kernels, Network appliances/NFV using Linux kernel. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63993?
Install vendor kernel updates or backports; block/unexpose VXLAN endpoints until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Use-after-free in VXLAN via crafted packets leading to kernel memory corruption, DoS, or privilege escalation/remote kernel code execution.
Immediate action required
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < 6b8bfce9d2f774d2c2243e0248e03efb99bba6c0
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < 9257f56ac47ef1976bcd056cf986a9988eeec67a
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < 8d435d68d71fb875876b722f4136caf74f2f48bd
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < dc3bfa050f873371e745bdf478b1f5b738e5733d
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < 609e63312c29aad18026a1d3222e123d4b6b0feb
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < 5303925e360527243b46a440a04667826bbc72b7
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < a493efd4336cf19122ae0e4cbb3d31b32d70deea
- affected>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f and < 7d9ef0cb271555d8cf39fefe6c981e1493b25ecf
- affected5.9
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.