CVE-2026-63983
CVE CVE-2026-63983EUVD EUVD-2026-45756Published 2026-07-19T14:56:06.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: net/sched: fix packet loop on netem when duplicate is on When netem duplicates a packet it re-enqueues the copy at the root qdisc. If another netem sits in the tree the copy can be duplicated again, recursing until the stack or memory is exhausted. The original duplication guard temporarily zeroed q->duplicate around the re-enqueue, but that does not cover all cases because it is per-qdisc state shared across all concurrent enqueue paths and is not safe without additional locking. Use the skb tc_depth field introduced in an earlier patch: - increment it on the duplicate before re-enqueue - skip duplication for any skb whose tc_depth is already non-zero. This marks the packet itself rather than mutating qdisc state, therefore it is safe regardless of tree topology or concurrency.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.1; 0afb51e72855971dba83b3c6b70c547c2d1161fd <1a298a514ce766c6d0c232991a390fec67af81ad; 2.6.12; patch: 6.12.93; 0afb51e72855971dba83b3c6b70c547c2d1161fd <9552b11e3edabc97cfcd9f29103d5afbce7ae183; patch: 0; patch: 7.0.12; 0afb51e72855971dba83b3c6b70c547c2d1161fd <cfb2616042767ab31260d4f39190c381bec8b12e
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.