Get real-time updates on Telegram
CVE-2026-63999: linux kernel 6.15; +1 more affected products
CVE-2026-63999. CVSS 3.1 base score 5.5 (MEDIUM, NVD). EPSS 0.00166 (percentile 0.05308), scored 2026-10-06.
Affected technology
linux kernel · from 5.15.181 (inclusive), before 5.16 (exclusive)
linux
linux kernel · from 6.1.135 (inclusive), before 6.2 (exclusive)
linux
linux kernel · from 6.6.88 (inclusive), before 6.7 (exclusive)
linux
linux kernel · from 6.12.24 (inclusive), before 6.13 (exclusive)
linux
linux kernel · from 6.13.12 (inclusive), before 6.14 (exclusive)
linux
linux kernel · from 6.14.3 (inclusive), before 6.15 (exclusive)
linux
linux kernel · from 6.15.1 (inclusive), before 6.18.35 (exclusive)
linux
linux kernel · from 6.19 (inclusive), before 7.0.12 (exclusive)
linux
linux kernel · 6.15
linux
linux kernel · 6.15 · update rc2
linux
linux kernel · 6.15 · update rc3
linux
linux kernel · 6.15 · update rc4
linux
linux kernel · 6.15 · update rc5
linux
linux kernel · 6.15 · update rc6
linux
linux kernel · 6.15 · update rc7
linux
linux kernel · 7.1 · update rc1
linux
linux kernel · 7.1 · update rc2
linux
linux kernel · 7.1 · update rc3
linux
linux kernel · 7.1 · update rc4
linux
linux kernel · 7.1 · update rc5
linux
Linux · 4f038a6a02d20859a3479293cbf172b0f14cbdd6 to before 33d05c22d6f227c5ae171c46df2f6f8bf48047ea, 4f038a6a02d20859a3479293cbf172b0f14cbdd6 to before 80d95d92f828cfcace955d673637d944178b435f, 4f038a6a02d20859a3479293cbf172b0f14cbdd6 to before 266297692f97008ca48bc311775c087c59bd7fe3, 81a5174e64ce4fb7b7a2f6499b835c904c9451ee, ec9faff49a4ea27731de39cb887b7e590e93157b, c5ed0eaddcbda56079091fc3876b140a6e70a548, a065b996052656a65afc51ad82336dc55ae4c72f, adee9db710a6117b978a25ed4153846b7c56ec9a, 5eb3fdc4b6281b29e830300c866a36d90442b1f0, 5.15.181 to before 5.16, 6.1.135 to before 6.2, 6.6.88 to before 6.7, 6.12.24 to before 6.13, 6.13.12 to before 6.14, 6.14.3 to before 6.15
Linux
Linux · 6.15
Linux
Component: Not specified by the source
Function: returns
File: net/ethtool/rss.c
Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required
What an attacker can do
NVD’s CVSS 3.1 assessment (base score 5.5/10) rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-401
- CCR priority
- 22.0 /100 (P4)
- CVSS 3.1
- 5.5 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H · NVD
- EPSS
- 0.00166 · percentile 0.05338 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-63999.html