CVE-2026-53362

Linux Kernel: Unspecified

As of , CVE-2026-53362 in Linux Kernel is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch now.

Exploited
Yes: CISA listed it on 27 August 2026
US federal deadline
30 August 20263 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
Forensic triage
Required by CISA under BOD 26-04Agencies must also look for signs that attackers already got in.
EPSS score
0.01Higher than 51% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: git.kernel.orgLinks below, from CISA's entry.

What CISA says to do

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA's required action

What the flaw is

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

CISA's description

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen.

The CVE record's description, from Linux, shortened; full text on cve.org

CVE published
4 July 2026
Assigned by
Linux
CVSS
7.8 High (CVSS 3.1, from the CNA)
CWE-122
Heap-based Buffer Overflow
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Kernel: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-39682Improper Check for Unusual or Exceptional ConditionsLinux KernelPatch nowForensic triage required by CISA0.03
CVE-2025-39964Race ConditionLinux KernelPatch nowForensic triage required by CISA0.01
CVE-2026-53266Out-of-Bounds WriteLinux KernelPatch nowForensic triage required by CISA0.01
CVE-2021-22555Heap Out-of-Bounds WriteLinux KernelPatch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry0.79
CVE-2013-6282Improper Input ValidationLinux KernelPatch this weekMetasploit module; verified Exploit-DB entry0.40
CVE-2019-13272Improper Privilege ManagementLinux KernelPatch this weekMetasploit module; EPSS 0.52; verified Exploit-DB entry0.52
CVE-2010-3904Improper Input ValidationLinux KernelPatch this weekMetasploit module; verified Exploit-DB entry0.16
CVE-2022-0847Privilege EscalationLinux KernelPatch this weekMetasploit module; EPSS 0.930.93
CVE-2021-3493Privilege EscalationLinux KernelPatch this weekMetasploit module0.49
CVE-2014-3153Privilege EscalationLinux KernelPatch this weekMetasploit module0.37

All 31 entries for Kernel

Read further