Get real-time updates on Telegram
CVE-2026-63992: linux kernel from 5.9 (inclusive), before 5.10.259 (exclusive), from 5.11 (inclusive), before 5.15.210 (exclusive)…
CVE-2026-63992. CVSS 3.1 base score 9.1 (CRITICAL, Source advisory). EPSS 0.00514 (percentile 0.41838), scored 2026-10-06.
Affected technology
linux kernel · from 5.9 (inclusive), before 5.10.259 (exclusive)
linux
linux kernel · from 5.11 (inclusive), before 5.15.210 (exclusive)
linux
linux kernel · from 5.16 (inclusive), before 6.1.176 (exclusive)
linux
linux kernel · from 6.2 (inclusive), before 6.6.143 (exclusive)
linux
linux kernel · from 6.7 (inclusive), before 6.12.93 (exclusive)
linux
linux kernel · from 6.13 (inclusive), before 6.18.35 (exclusive)
linux
linux kernel · from 6.19 (inclusive), before 7.0.12 (exclusive)
linux
linux kernel · 7.1 · update rc1
linux
linux kernel · 7.1 · update rc2
linux
linux kernel · 7.1 · update rc3
linux
linux kernel · 7.1 · update rc4
linux
linux kernel · 7.1 · update rc5
linux
Linux · 4cb47a8644cc9eb8ec81190a50e79e6530d0297f to before 5a92cb45e34749865d03daf8d3500f77b5f6644c, 4cb47a8644cc9eb8ec81190a50e79e6530d0297f to before c7b7ec3e69e673c0d6b57f74d21da50c485c598e, 4cb47a8644cc9eb8ec81190a50e79e6530d0297f to before 7f4f7efe7f30edd29c4988de01728bf2398217e4, 4cb47a8644cc9eb8ec81190a50e79e6530d0297f to before e917d0c69f01af2bb4fbea2b66d560a53b3ac7ec, 4cb47a8644cc9eb8ec81190a50e79e6530d0297f to before a096b6e34f602950af9a2b0856cd93a5f4c276d7, 4cb47a8644cc9eb8ec81190a50e79e6530d0297f to before 43368636c663cff6e59dde93cf4b8e43ac28eb93, 4cb47a8644cc9eb8ec81190a50e79e6530d0297f to before cb549df9ce4ee15c9d5b19ddab12cf2128e4313c, 4cb47a8644cc9eb8ec81190a50e79e6530d0297f to before 509323077ef79a26ba0c60bb556e45c12c398b2d
Linux
Linux · 5.9
Linux
Component: Not specified by the source
File: net/ipv4/ip_tunnel_core.c
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 9.1/10) rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-125
- CCR priority
- 36.5 /100 (P4)
- CVSS 3.1
- 9.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H · Source advisory
- EPSS
- 0.00514 · percentile 0.41838 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 23:02:50.240617+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-63992.html