CVE-2026-63801 | Linux Kernel up to 7.1.2 Tipc net/tipc/crypto.c tipc_aead_decrypt_done stats/net use after free (EUVD-2026-45467)
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 7.1.2. The affected element is the function tipc_aead_decrypt_done of the file net/tipc/crypto.c of the component Tipc. Such manipulation of the…
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 7.1.2. The affected element is the function tipc_aead_decrypt_done of the file net/tipc/crypto.c of the component Tipc. Such manipulation of the argument stats/net leads to use after free.
This vulnerability is traded as CVE-2026-63801. The attack may be launched remotely. There is no exploit available.
Verschlüsselung im Ruhezustand & Unveränderbare SIEM-Logs
Geschützt (KMS Envelope Encryption)
Angreifer penetrieren Perimeter und WAF ungehindert. Schicht 3 (Micro-Segmentierung & Port-Drop) bildet die entscheidende Stop-Linie zur Schadenseindämmung.
Analyse für CVE-2026-63801 auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: nein. Handlungsableitung aus den verlinkten Hersteller-Quellen.
🛡️ Angriffsfläche & Exposure
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
⚡ Empfohlene Sofortmaßnahmen
1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Verwandte Schwachstellen (gleicher Hersteller)
CVE-2026-74705CVE-2026-74705 | In the Linux kernel, the following vulnerability has been resolved:
udp: fix potential use-after-free in tunnel segmentation
__skb_udp_tunnel_segment() gets the UDP header before ensuring the
tunnel header is in the skb head. If the pull reallocates skb->head,
the saved UDP header pointer is no longer valid.
Get the UDP header after the pull to avoid a potential use-after-free.
CVSS 10.0
CVE-2026-74612CVE-2026-74612 | In the Linux kernel, the following vulnerability has been resolved:
veth: fix skb length accounting after XDP frag adjustment
veth exposes non-linear skb fragments through an xdp_buff. If an XDP
program adjusts the fragment area, veth_xdp_rcv_skb() copies
xdp_frags_size back to skb->data_len but leaves skb->len containing the
old fragment contribution.
After a fragment shrink, this makes skb_headlen() larger than the actual
linear area. In the reproduced U
CVSS 10.0
CVE-2026-74475CVE-2026-74475 | In the Linux kernel, the following vulnerability has been resolved:
vxlan: use neigh_ha_snapshot() in route_shortcircuit()
The neighbour hardware address n->ha can be updated asynchronously by the
neighbour subsystem, protected by n->ha_lock seqlock. Reading n->ha without
holding the seqlock loop can lead to torn reads or reading a partially updated
MAC address.
Use neigh_ha_snapshot() in route_shortcircuit() to safely copy n->ha under
read_seqbegin()/read
CVSS 10.0
Synthetische RAG-Antwort
HAND-OFF
Auf Smartphone übergeben (CVE-2026-63801)
Scannen Sie den QR-Code mit der Smartphone-Kamera für sofortigen mobilen Zugriff:
Auch interessante Nachrichten CVE-2026-63801 | Linux Kernel up to 7.1.2 Tipc net/tipc/crypto.c tipc_aead_decrypt_done stats/net use after free (EUVD-2026-45467)