Insufficient verification of data authenticity in Linux kernel - CVE-2026-63913
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state validation in the TCP conntrack state machine in netfilter conntrack when processing a crafted SYN followed by an invalid-sequence RST packet. A remote attacker can send a specially crafted packet sequence to cause a denial of service.
The issue can prematurely terminate an active NAT entry by forcing the conntrack entry into the CLOSE state.
How to mitigate CVE-2026-63913
Sources
- https://git.kernel.org/stable/c/2006979a15af5404bf932a325357683c0bac1656
- https://git.kernel.org/stable/c/2bb6d82b586ea5a4cb73bbdd6b7432e96096bc77
- https://git.kernel.org/stable/c/6476c17d536dbd321c073242e762ddb2713a1238
- https://git.kernel.org/stable/c/b98ab51c45c5608a1c19ce7fd17a3032469bb83f
- https://git.kernel.org/stable/c/bed6e04be8e6b9133d8b16d5a42d0e0ce674fa9a
- https://git.kernel.org/stable/c/d67c6adee8d1b65330d0174c4c367faba14e80a8
- https://git.kernel.org/stable/c/f206def4e86d810f927ba1d8e322ea72b29bce58
- https://git.kernel.org/stable/c/f5547bebc416d56f56fb5b86dc20aabfa42165a0