Insufficient verification of data authenticity in Linux kernel - CVE-2026-63913
Published: July 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state validation in the TCP conntrack state machine in netfilter conntrack when processing a crafted SYN followed by an invalid-sequence RST packet. A remote attacker can send a specially crafted packet sequence to cause a denial of service.
The issue can prematurely terminate an active NAT entry by forcing the conntrack entry into the CLOSE state.
Affected software
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
openEuler
Ubuntu
kernel (Red Hat package)
kernel-rt (Red Hat package)
bpftool-debuginfo
python3-perf-debuginfo
python3-perf
perf-debuginfo
perf
kernel-tools-devel
kernel-tools-debuginfo
kernel-tools
kernel-source
kernel-headers
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool
kernel
linux-ibm (Ubuntu package)
linux-aws (Ubuntu package)
linux-azure (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-63913
kernel (Red Hat package) - update to 4.18.0-553.158.1.el8_10
kernel-rt (Red Hat package) - update to 4.18.0-553.158.1.rt7.499.el8_10
bpftool-debuginfo - update to 5.10.0-331.0.0.232
python3-perf-debuginfo - update to 5.10.0-331.0.0.232
python3-perf - update to 5.10.0-331.0.0.232
perf-debuginfo - update to 5.10.0-331.0.0.232
perf - update to 5.10.0-331.0.0.232
kernel-tools-devel - update to 5.10.0-331.0.0.232
kernel-tools-debuginfo - update to 5.10.0-331.0.0.232
kernel-tools - update to 5.10.0-331.0.0.232
kernel-source - update to 5.10.0-331.0.0.232
kernel-headers - update to 5.10.0-331.0.0.232
kernel-devel - update to 5.10.0-331.0.0.232
kernel-debugsource - update to 5.10.0-331.0.0.232
kernel-debuginfo - update to 5.10.0-331.0.0.232
bpftool - update to 5.10.0-331.0.0.232
kernel - update to 5.10.0-331.0.0.232
linux-ibm (Ubuntu package) - addressed in versions 7.0.0-1008.8, 7.0.0-1010.10
linux-aws (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1015.15
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-nvidia (Ubuntu package) - addressed in versions 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16
External References
- https://git.kernel.org/stable/c/2006979a15af5404bf932a325357683c0bac1656
- https://git.kernel.org/stable/c/2bb6d82b586ea5a4cb73bbdd6b7432e96096bc77
- https://git.kernel.org/stable/c/6476c17d536dbd321c073242e762ddb2713a1238
- https://git.kernel.org/stable/c/b98ab51c45c5608a1c19ce7fd17a3032469bb83f
- https://git.kernel.org/stable/c/bed6e04be8e6b9133d8b16d5a42d0e0ce674fa9a
- https://git.kernel.org/stable/c/d67c6adee8d1b65330d0174c4c367faba14e80a8
- https://git.kernel.org/stable/c/f206def4e86d810f927ba1d8e322ea72b29bce58
- https://git.kernel.org/stable/c/f5547bebc416d56f56fb5b86dc20aabfa42165a0
Related Security Bulletins
- Insufficient verification of data authenticity in Linux kernel netfilter
- Ubuntu update for linux-ibm
- Ubuntu update for linux-azure
- Ubuntu update for linux-aws
- Ubuntu update for linux-nvidia-bos
- Ubuntu update for linux-nvidia
- Red Hat Enterprise Linux 8 update for kernel-rt
- Red Hat Enterprise Linux 8 update for kernel
- openEuler 22.03 LTS SP4 update for kernel