Integer underflow in Linux kernel - CVE-2026-63868
Published: July 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unsigned integer underflow in garp_pdu_parse_attr in the GARP receive-side attribute parser when parsing crafted GARP attributes. A remote attacker can send crafted Join or Leave events to cause a denial of service.
The issue can cause received GARP events for common attributes, such as GVRP VLAN registration attributes, to be ignored.
Affected software
How to mitigate CVE-2026-63868
External References
- https://git.kernel.org/stable/c/04e22fefac1af3e32f245e9045382348773b5d59
- https://git.kernel.org/stable/c/16e408e607a94b646fb14a2a98422c6877ae4b3c
- https://git.kernel.org/stable/c/29f28172afb2ae7b31e9bf3e978396f20b381688
- https://git.kernel.org/stable/c/74e02121be1dcc0efcd56ebdf0171d6129105659
- https://git.kernel.org/stable/c/973cf7c433d27f4d9556d0b7c332543be7ed7a6e
- https://git.kernel.org/stable/c/a11f1a671b1361f0f1278dc0041374f2730df73f
- https://git.kernel.org/stable/c/d4c86ea09ae3e63ee5aa86e941fcc38e0e39874a
- https://git.kernel.org/stable/c/d8dcd14aa886b8effd83022c550669f4f262854b