Answer in brief
CVE-2026-63912 records a Unknown severity vulnerability in xfrm: esp: restore combined single-frag length gate. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-63912 records a Unknown severity vulnerability in xfrm: esp: restore combined single-frag length gate. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c075c3ea031757f8ea2d34567565b61a868c08d5 <566295735530ee513326049b0540f32ec050bf2e || >=a583f2f3c8788bffd7fd7baeb76bd6d80543d7ea <5d7ab86e2b6bc23054616bf6ac562013bf60af8c || >=5bd8baab087dff657e05387aee802e70304cc813 <36519e3d941fc99d3b52c134dbaf311f987a4708 || >=5bd8baab087dff657e05387aee802e70304cc813 <322e48187e0245ab2fff6fec2220b0cae677dbec || >=5bd8baab087dff657e05387aee802e70304cc813 <b84091ceddc9f133229dceab3ccc930bf27f9cba || >=5bd8baab087dff657e05387aee802e70304cc813 <c093468aea8277f77272a4f199b2e15e19cabb59 || >=5bd8baab087dff657e05387aee802e70304cc813 <65f3b3fc2347b89fe21db1e92c7681368415f095 || >=5bd8baab087dff657e05387aee802e70304cc813 <dfa0d7b0ff1eb6b2c416b8fdb9b4f2cefba57a40 || 2c66b0c95bb0aa7652ba1eba293d0d5993b35a38 || ef6f83df1209a7d9bd1c605a62457d4c00f9179e || 3defefd22ad5fbbe639b6157fb7e6311b2bf333d || b657030870bb5351c5b1e84d4e9f186da6ca0496 || >=5.10.113 <5.10.259 || >=5.15.36 <5.15.210 || >=4.14.288 <4.15 || >=4.19.252 <4.20 || >=5.4.205 <5.5 || >=5.17.5 <5.18 | 566295735530ee513326049b0540f32ec050bf2e, 5d7ab86e2b6bc23054616bf6ac562013bf60af8c, 36519e3d941fc99d3b52c134dbaf311f987a4708, 322e48187e0245ab2fff6fec2220b0cae677dbec, b84091ceddc9f133229dceab3ccc930bf27f9cba, c093468aea8277f77272a4f199b2e15e19cabb59, 65f3b3fc2347b89fe21db1e92c7681368415f095, dfa0d7b0ff1eb6b2c416b8fdb9b4f2cefba57a40, 5.10.259, 5.15.210, 4.15, 4.20, 5.5, 5.18 |
| Linux/Linuxgeneric | 5.18 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer in esp_output_head() before esp_output_tail() allocates the destination page frag. The head-side gate currently checks skb->data_len and tailen separately, but the tail code allocates a single destination frag from the combined post-trailer skb->data_len. Reject the page-frag fast path when the combined aligned length exceeds a page. Otherwise skb_page_frag_refill() may fall back to a single page while the destination sg still spans the combined skb->data_len. Restore this combined-length page gate for both IPv4 and IPv6.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c075c3ea031757f8ea2d34567565b61a868c08d5 <566295735530ee513326049b0540f32ec050bf2e || >=a583f2f3c8788bffd7fd7baeb76bd6d80543d7ea <5d7ab86e2b6bc23054616bf6ac562013bf60af8c || >=5bd8baab087dff657e05387aee802e70304cc813 <36519e3d941fc99d3b52c134dbaf311f987a4708 || >=5bd8baab087dff657e05387aee802e70304cc813 <322e48187e0245ab2fff6fec2220b0cae677dbec || >=5bd8baab087dff657e05387aee802e70304cc813 <b84091ceddc9f133229dceab3ccc930bf27f9cba || >=5bd8baab087dff657e05387aee802e70304cc813 <c093468aea8277f77272a4f199b2e15e19cabb59 || >=5bd8baab087dff657e05387aee802e70304cc813 <65f3b3fc2347b89fe21db1e92c7681368415f095 || >=5bd8baab087dff657e05387aee802e70304cc813 <dfa0d7b0ff1eb6b2c416b8fdb9b4f2cefba57a40 || 2c66b0c95bb0aa7652ba1eba293d0d5993b35a38 || ef6f83df1209a7d9bd1c605a62457d4c00f9179e || 3defefd22ad5fbbe639b6157fb7e6311b2bf333d || b657030870bb5351c5b1e84d4e9f186da6ca0496 || >=5.10.113 <5.10.259 || >=5.15.36 <5.15.210 || >=4.14.288 <4.15 || >=4.19.252 <4.20 || >=5.4.205 <5.5 || >=5.17.5 <5.18 | 566295735530ee513326049b0540f32ec050bf2e, 5d7ab86e2b6bc23054616bf6ac562013bf60af8c, 36519e3d941fc99d3b52c134dbaf311f987a4708, 322e48187e0245ab2fff6fec2220b0cae677dbec, b84091ceddc9f133229dceab3ccc930bf27f9cba, c093468aea8277f77272a4f199b2e15e19cabb59, 65f3b3fc2347b89fe21db1e92c7681368415f095, dfa0d7b0ff1eb6b2c416b8fdb9b4f2cefba57a40, 5.10.259, 5.15.210, 4.15, 4.20, 5.5, 5.18 |
| Linux/Linuxgeneric | 5.18 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer in esp_output_head() before esp_output_tail() allocates the destination page frag. The head-side gate currently checks skb->data_len and tailen separately, but the tail code allocates a single destination frag from the combined post-trailer skb->data_len. Reject the page-frag fast path when the combined aligned length exceeds a page. Otherwise skb_page_frag_refill() may fall back to a single page while the destination sg still spans the combined skb->data_len. Restore this combined-length page gate for both IPv4 and IPv6.
Quoted source text, attributed separately from HOL analysis.