Sploitus

CVE-2026-63870

No indexed exploits for CVE-2026-63870 yet

In the Linux kernel, the following vulnerability has been resolved: ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() The aoe driver (or similar) generates a non-IPv6 packet (e.g., ETH_P_AOE) and queues it for transmission via dev_queue_xmit() on a 6LoWPAN interface (configured by the user or test case). Since the packet is not IPv6, the 6LoWPAN header_ops->create function (lowpan_header_create or header_create) returns early without initializing the lowpan_addr_info structure in the skb headroom. In the transmit function (lowpan_xmit), the driver calls lowpan_header (or setup_header) which unconditionally copies and uses the lowpan_addr_info from the headroom, which contains uninitialized data. Fix this by dropping non IPv6 packets. A similar fix is needed in net/bluetooth/6lowpan.c bt_xmit().

CVSS 3.1
7.8 HIGH
EPSS
0.1% (2th percentile)
NVD status
Awaiting Analysis
Published
2026-07-19
CVE-2026-63870 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-63870 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-63870 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.