CVE-2026-90063
In the Linux kernel, the following vulnerability has been resolved: virtio-net: Ensure that TCP packets don't overflow gso_segs The user can specify any gso_size in a packet crafted with an AF_PACKET PACKET_VNET_HDR socket, even smaller than TCP_MIN_GSO_SIZE = 8. At the same time, GSO_MAX_SIZE = 8 * GSO_MAX_SEGS = 8 * 65535. When the user crafts a packet with gso_size < 8, there is a risk for partial GSO to overflow the 16-bit gso_segs field when dividing the SKB length by gso_size. Adjust gso_size of TCP packets to be at least TCP_MIN_GSO_SIZE = 8. Keep gso_size of UDP GSO packets, as gso_size=1 is valid and explicitly tested at tools/testing/selftests/net/tun.c:649.
Affected versions
Linux kernel versions
4.14.187,
4.19.131,
5.4.46,
5.6.18,
5.7
and later are affected. Fixed in
5.15.221,
6.1.188,
6.6.157,
6.12.110,
6.18.52,
7.2.6,
7.3-rc1
and their respective stable series.
References
7 totalFrequently asked questions
-
What is CVE-2026-90063?
CVE-2026-90063 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 4.14.187 onward and has been patched in 5.15.221, 6.1.188, 6.6.157 and others. CVE-2026-90063 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-90063?
Yes. CVE-2026-90063 has been patched. Fixed versions include 5.15.221, 6.1.188, 6.6.157 and others. If you are running Linux kernel 4.14.187 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-90063 actively exploited?
No. CVE-2026-90063 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.