SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-63991

UNKNOWN · CVSS N/A EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's Bluetooth 6lowpan implementation, where the send_mcast_pkt() function fails to check the return value of skb_clone(), potentially leading to a NULL pointer dereference in send_pkt(). This flaw could result in system crashes or instability when memory allocation fails during multicast packet sending. Organizations using Linux systems with Bluetooth capabilities should prioritize addressing this issue to maintain system reliability and security.

CVE
CVE-2026-63991
Severity
UNKNOWN
CVSS
N/A
EPSS
0.18%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() The skb_clone() function can return NULL if memory allocation fails. send_mcast_pkt() calls skb_clone() without checking the return value, which can lead to a NULL pointer dereference in send_pkt() when it dereferences skb->data. Add a NULL check after skb_clone() and skip the peer if the clone fails.