Vulnerability
Published 2026-08-27
Verified 2026-09-19
Linux IPv6 fragmentation out-of-bounds write (CVE-2026-53362)
Out-of-bounds write in the Linux IPv6 send path (__ip6_append_data) when the paged-allocation branch undersizes the linear skb by fraggap bytes. An unprivileged local user can trigger it with a UDPv6 socket using MSG_MORE and MSG_SPLICE_PAGES. kernel.org rates CVSS 7.8. Red Hat describes the same flaw as a privilege-escalation and container-escape path on affected kernels. Patch to 6.1.177, 6.6.144, 6.12.95, 6.18.38 or 7.1.3, or the distro kernel that carries those stable commits. Red Hat documents a temporary workaround of user.max_user_namespaces=0; that setting breaks some container workflows.
- Product
- Linux kernel (IPv6)
- Versions
- From 6.0 until 6.1.177 / 6.6.144 / 6.12.95 / 6.18.38 / 7.1.3
- CVSS
- (CVSS 3.1, kernel.org CNA)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- 6.1.177 / 6.6.144 / 6.12.95 / 6.18.38 / 7.1.3 or distro equivalent
Primary: NVD · Vendor: Red Hat RHSB-2026-009 · CVE: CVE-2026-53362 · kernel.org stable commit
