Vulnerability
Published 2026-08-27
Verified 2026-09-19

Linux IPv6 fragmentation out-of-bounds write (CVE-2026-53362)

Out-of-bounds write in the Linux IPv6 send path (__ip6_append_data) when the paged-allocation branch undersizes the linear skb by fraggap bytes. An unprivileged local user can trigger it with a UDPv6 socket using MSG_MORE and MSG_SPLICE_PAGES. kernel.org rates CVSS 7.8. Red Hat describes the same flaw as a privilege-escalation and container-escape path on affected kernels. Patch to 6.1.177, 6.6.144, 6.12.95, 6.18.38 or 7.1.3, or the distro kernel that carries those stable commits. Red Hat documents a temporary workaround of user.max_user_namespaces=0; that setting breaks some container workflows.

Product
Linux kernel (IPv6)
Versions
From 6.0 until 6.1.177 / 6.6.144 / 6.12.95 / 6.18.38 / 7.1.3
CVSS
(CVSS 3.1, kernel.org CNA)
Exploited in Australia?
unknown
Patch to
6.1.177 / 6.6.144 / 6.12.95 / 6.18.38 / 7.1.3 or distro equivalent

Primary: NVD · Vendor: Red Hat RHSB-2026-009 · CVE: CVE-2026-53362 · kernel.org stable commit

vulnerabilities