SB20260720409 - Integer underflow in Linux kernel 802
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer underflow (CVE-ID: CVE-2026-63868)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unsigned integer underflow in garp_pdu_parse_attr in the GARP receive-side attribute parser when parsing crafted GARP attributes. A remote attacker can send crafted Join or Leave events to cause a denial of service.
The issue can cause received GARP events for common attributes, such as GVRP VLAN registration attributes, to be ignored.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/04e22fefac1af3e32f245e9045382348773b5d59
- https://git.kernel.org/stable/c/16e408e607a94b646fb14a2a98422c6877ae4b3c
- https://git.kernel.org/stable/c/29f28172afb2ae7b31e9bf3e978396f20b381688
- https://git.kernel.org/stable/c/74e02121be1dcc0efcd56ebdf0171d6129105659
- https://git.kernel.org/stable/c/973cf7c433d27f4d9556d0b7c332543be7ed7a6e
- https://git.kernel.org/stable/c/a11f1a671b1361f0f1278dc0041374f2730df73f
- https://git.kernel.org/stable/c/d4c86ea09ae3e63ee5aa86e941fcc38e0e39874a
- https://git.kernel.org/stable/c/d8dcd14aa886b8effd83022c550669f4f262854b