Build. Connect. Analyse.

The Security team has detected a vulnerability with a high severity. This document will provide a brief description of the vulnerability, a list of affected operating systems and/or software.   

Overview of the Vulnerability:  

CVE-2026-53362 is a heap buffer overflow vulnerability in the Linux kernel’s IPv6 networking stack, specifically in the __ip6_append_data() function within the paged-allocation code path. A flaw in the way the kernel accounts for “fraggap” bytes — data carried over from a previous socket buffer — when computing the sizes of the linear and paged regions of a new socket buffer means that the linear area is undersized. This causes the kernel to write past the end of the allocated buffer into the trailing skb_shared_info structure, corrupting kernel memory. An unprivileged local user can trigger this condition, potentially leading to a denial of service (kernel crash) or, in the worst case, privilege escalation on the affected host. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalogue on the 27th of August. 

Affected software:  

  • Linux kernel versions affected by commits 773ba4fe9104 and ce650a166335 (prior to the stable-series fixes in 6.x) 
  • Ubuntu 20.04 – 25.04 
  • SUSE Linux Enterprise Server 15 SP5 – 15 SP6 
  • SUSE Linux Enterprise Micro 5.3 – 5.5 
  • Debian bookworm (6.1 kernel series) 
  • Debian bullseye (5.10 kernel series) 
  • Red Hat Enterprise Linux 8 – 9 

Immediate Actions Required:  

  • Apply the latest kernel patch provided by your Linux distribution vendor to remediate this vulnerability — this is the primary and most effective remediation. 
  • Reboot affected systems after patching, as kernel updates do not take effect until the system is restarted unless a live patching service is in use. 
  • Where patching is not immediately possible, restrict the ability of unprivileged users to send UDPv6 traffic using MSG_MORE and MSG_SPLICE_PAGES, and consider limiting local and shell access to trusted administrators only. 
  • Confirm remediation by verifying the running kernel version with “uname -r” and comparing it against the fixed version published by your vendor. 
  • Monitor vendor security channels and threat intelligence feeds for further indicators of compromise and updated guidance as they become available. 

Further Information:  

For detailed information on the vulnerability, please refer to the following sources: 

https://nvd.nist.gov/vuln/detail/CVE-2026-53362 

https://ubuntu.com/security/CVE-2026-53362 

https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962 

Ready to talk? Discuss your low-latency compute requirements with our sales team