Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-63911

7.8 · HIGH
Published Jul 19, 2026 EPSS 0.16% (6th pctl)

Overview

CVE-2026-63911 is a high-severity vulnerability. It was published on July 19, 2026 and has a CVSS 3.1 base score of 7.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

xfrm: iptfs: reset runtime state when cloning SAs

iptfs_clone_state() clones the IPTFS mode data with kmemdup(). This

copies runtime objects which must not be shared with the original SA,

including the embedded sk_buff_head, hrtimers, spinlock, and in-flight

reassembly/reorder state.

If xfrm_state_migrate() fails after clone_state() but before the later

init_state() call has reinitialized those fields, the cloned state can be

destroyed by xfrm_state_gc_task() with list and timer state copied from the

original SA. With queued packets this lets the clone splice and free skbs

owned by the original IPTFS queue, leading to use-after-free and

double-free reports in iptfs_destroy_state() and skb release paths.

Reinitialize the clone's runtime state before publishing it through

x->mode_data. Because clone_state() now publishes a destroyable mode_data

object before init_state(), take the mode callback module reference there

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-63911?

CVE-2026-63911 is a high-severity vulnerability. It was published on July 19, 2026 and has a CVSS 3.1 base score of 7.8 (HIGH).

How severe is CVE-2026-63911?

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2026-63911?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-63911?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-63911 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.