CVE-2026-63868
CVE CVE-2026-63868EUVD EUVD-2026-45553Published 2026-07-19T14:18:37.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr The receive-side GARP attribute parser computes dlen with reversed operands: dlen = sizeof(*ga) - ga->len; ga->len is the on-wire attribute length and includes the GARP attribute header. For normal attributes with data, ga->len is larger than sizeof(*ga), so the subtraction underflows in unsigned arithmetic. The resulting value is later passed to garp_attr_lookup(), whose length argument is u8. After truncation, the parsed data length usually no longer matches the length stored for locally registered attributes, so received Join/Leave events are ignored. This breaks the GARP receive path for common attributes, such as GVRP VLAN registration attributes. Compute the data length as the attribute length minus the header length.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 2.6.27; eca9ebac651f774d8b10fce7c5d173c3c3d3394f <74e02121be1dcc0efcd56ebdf0171d6129105659; patch: 6.1.176; eca9ebac651f774d8b10fce7c5d173c3c3d3394f <16e408e607a94b646fb14a2a98422c6877ae4b3c; eca9ebac651f774d8b10fce7c5d173c3c3d3394f <a11f1a671b1361f0f1278dc0041374f2730df73f; patch: 6.18.36; eca9ebac651f774d8b10fce7c5d173c3c3d3394f <29f28172afb2ae7b31e9bf3e978396f20b381688; patch: 6.6.143; eca9ebac651f774d8b10fce7c5d173c3c3d3394f <04e22fefac1af3e32f245e9045382348773b5d59; eca9ebac651f774d8b10fce7c5d173c3c3d3394f <973cf7c433d27f4d9556d0b7c332543be7ed7a6e; patch: 7.1; patch: 0; patch: 7.0.13; patch: 5.10.259; eca9ebac651f774d8b10fce7c5d173c3c3d3394f <d4c86ea09ae3e63ee5aa86e941fcc38e0e39874a; patch: 6.12.94; patch: 5.15.210; eca9ebac651f774d8b10fce7c5d173c3c3d3394f <d8dcd14aa886b8effd83022c550669f4f262854b
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.