Actively exploited vulnerability
Linux Kernel: privilege escalation flaw under attack
CVE-2026-53362 · Linux Kernel Unspecified Vulnerability
What is affected
Linux Kernel is found on ordinary personal computers and phones, so this is not only a problem for companies. If you use it and have not updated since the fix was released, you are exposed.
Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.
What an attacker can do
This is a privilege escalation flaw. It lets an attacker turn limited access into full administrator control. Attackers pair it with another flaw or a malicious file: once anything of theirs runs on the device, this bug lets it take over completely.
- How it is reached
- Needs access to the device or a file opened on it
- Access the attacker needs
- A basic user account
- Does the victim have to do something?
- No, works without the victim doing anything
What to do
- Update Linux Kernel now. Open the update or "About" screen, install whatever is offered and restart the app or device, because the fix is not active until you do.
- Turn on automatic updates so the next fix arrives without you having to look for it.
- If your device is too old to receive this update, stop using the affected app for anything sensitive and plan a replacement.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Vendor advisories and fixes
- git.kernel.orggit.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962
- git.kernel.orggit.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769
- git.kernel.orggit.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d
- git.kernel.orggit.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a
- git.kernel.orggit.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e
- git.kernel.orggit.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5
How urgent is it
CISA added this vulnerability to its Known Exploited Vulnerabilities catalogue on August 27, 2026, which means there is reliable evidence of attacks in the wild. US federal agencies must fix it by August 30, 2026, a deadline that has already passed. That deadline does not bind anyone else, but it shows how seriously the agency rates it.
The EPSS model estimates a 0.7% probability that this flaw will be exploited somewhere in the next 30 days. That is higher than 52% of all scored vulnerabilities.
Its CVSS severity score is 7.8 out of 10 (high), as recorded in the US National Vulnerability Database.
Technical description
In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check.