Local privilege escalation via IPv6 buffer overflow
Published Jul 4, 2026 · Updated Aug 28, 2026
Heap buffer overflow in affected Linux kernels allows local users to gain kernel privileges through crafted UDPv6 socket operations. __ip6_append_data() omits fraggap from the paged allocation's linear size while counting those bytes as paged data, so their copy overruns skb->end into skb_shared_info. Triggering requires an unprivileged local process, IPv6 support, and a UDPv6 send sequence using MSG_MORE with MSG_SPLICE_PAGES; successful exploitation grants root-level control.
Summary
What happened
Heap buffer overflow in affected Linux kernels allows local users to gain kernel privileges through crafted UDPv6 socket operations. __ip6_append_data() omits fraggap from the paged allocation's linear size while counting those bytes as paged data, so their copy overruns skb->end into skb_shared_info. Triggering requires an unprivileged local process, IPv6 support, and a UDPv6 send sequence using MSG_MORE with MSG_SPLICE_PAGES; successful exploitation grants root-level control.
The record
- CVE
- CVE-2026-53362
- Published
- Jul 4, 2026
- Updated
- Aug 28, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- T1068
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Jul 4, 2026CVE publishedPublication date reported by the CVE source.
- Aug 27, 2026Exploitation reportedCISA Known Exploited Vulnerabilities Catalog listing
- Aug 28, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=6.0
- Affected versionversion=773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 <14200d435af9a9eeb444f529fc2f689a236b7962
- Affected versionversion=773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 <46f201f8b4c39633a1fa3dc12459f506d470993d
- Affected versionversion=773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 <6374fb9edf72c67a118a2c214a0dddd04c921e0a
- Affected versionversion=773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 <65fb14cbebb0cd0eff903a22d33537ddc8b95769
- Affected versionversion=773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 <736b380e28d0480c7bc3e022f1950f31fe53a7c5
- Affected versionversion=773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 <e9eacf19281ea2498b36291b56c9606118c2d74e
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- kernelCTF CVE-2026-53362_lts exploitfunctional · validated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Reported exploitation
- CISA Known Exploited Vulnerabilities Catalog listingknown exploited catalog
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo