CVE-2026-63912 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer in esp_output_head() before esp_output_tail() allocates the destination page frag. The head-side gate currently checks skb->data_len and tailen separately, but the tail code allocates a single destination frag from the combined post-trailer skb->data_len. Reject the page-frag fast path wh
In the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: restore combined single-frag length gate
The ESP out-of-place fast path appends the trailer in esp_output_head()
before esp_output_tail() allocates the destination page frag. The
head-side gate currently checks skb->data_len and tailen separately, but
the tail code allocates a single destination frag from the combined
post-trailer skb->data_len.
Reject the page-frag fast path when the combined aligned length exceeds a
page. Otherwise skb_page_frag_refill() may fall back to a single page while
the destination sg still spans the combined skb->data_len.
Restore this combined-length page gate for both IPv4 and IPv6.
- 🔗 git.kernel.org/stable/c/566295735530ee513326049b0540f32e…
- 🔗 git.kernel.org/stable/c/5d7ab86e2b6bc23054616bf6ac562013…
- 🔗 git.kernel.org/stable/c/36519e3d941fc99d3b52c134dbaf311f…
- 🔗 git.kernel.org/stable/c/322e48187e0245ab2fff6fec2220b0ca…
- 🔗 git.kernel.org/stable/c/b84091ceddc9f133229dceab3ccc930b…
- 🔗 git.kernel.org/stable/c/c093468aea8277f77272a4f199b2e15e…
- 🔗 git.kernel.org/stable/c/65f3b3fc2347b89fe21db1e92c768136…
- 🔗 git.kernel.org/stable/c/dfa0d7b0ff1eb6b2c416b8fdb9b4f2ce…
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-24 | 2026-10-08 |
|---|---|---|
| ≥90 % | 484 | 342 |
| ≥50 % | 1436 | 1061 |
| ≥10 % | 16 | 2 |
| <10 % | 30 | 562 |
CVE-2026-63912 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer in esp_output_head() before esp_output_tail() allocates the destination page frag. The head-side gate currently checks skb->data_len and tailen separately, but the tail code allocates a single destination frag from the combined post-trailer skb->data_len. Reject the page-frag fast path wh
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer in esp_output_head() before esp_output_tail() allocates the destina
Noch keine Analyse zu CVE-2026-63912
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.