CVE-2026-63968: Linux

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible infinite loop in fib6_select_path() Found while auditing the same pattern Sashiko reported in rt6_fill_node() [1]. Apply the same fix as commit f8d8ce1b515a ("ipv6: fix possible infinite loop in fib6_info_uses_dev()"). Writers holding tb6_lock can list_del_rcu(&first->fib6_siblings) without waiting for RCU readers; first->fib6_siblings.next then still points into the old ring and this softirq-side walker never reaches &first->fib6_siblings as its terminator. fib6_purge_rt() always WRITE_ONCE()s first->fib6_nsiblings to 0 before list_del_rcu(), so an inside-loop check is a reliable detach signal. [1] https://sashiko.dev/#/patchset/20260526020227.4857-1-jiayuan.chen%40linux.dev

Affected products

  • Linux Linux: from 6.1.128, before 6.1.176 (fixed in 6.1.176); from 6.6.75, before 6.6.143 (fixed in 6.6.143); from 6.12.2, before 6.12.93 (fixed in 6.12.93); from 6.11.11, before 6.12 (fixed in 6.12); from 6.13, before 6.18.35 (fixed in 6.18.35); from 6.19, before 7.0.12 (fixed in 7.0.12)

Published 2026-07-19. Last modified 2026-07-30.