Back to overview

CVE-2026-63991

Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() The skb_clone() function can return NULL if memory allocation fails. send_mcast_pkt() calls skb_clone() without checking the return value, which can lead to a NULL pointer dereference in send_pkt() when it dereferences skb->data. Add a NULL check after skb_clone() and skip the peer if the clone fails.

Metadata

CVE ID
CVE-2026-63991
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 14:56 UTC
Last updated
2026-07-19 14:56 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 18722c247023035b9e2e2a08a887adec2a9a6e49 < 9afcb5ea080af13aab37930da627db43bd277665, 18722c247023035b9e2e2a08a887adec2a9a6e49 < 9903a04becf059e44cccf625e23689b7d4378384, 18722c247023035b9e2e2a08a887adec2a9a6e49 < d630c4b25f36e0e68461561e4c70957ec37fdedd, 18722c247023035b9e2e2a08a887adec2a9a6e49 < b06203ac5f12929d79146bb9f063c2af1d679e63 …
Linux Linux 3.14, 0 < 3.14, 5.10.259 ≤ 5.10.*, 5.15.210 ≤ 5.15.* …
Back to overview