2026-08-28 · view entry permalink →
Linux kernel IPv6 UDP fraggap accounting bug (CVE-2026-53362) added to CISA KEV — an unprivileged local heap overflow via MSG_SPLICE_PAGES, no exploitation narrative published
CISA added CVE-2026-53362 to its Known Exploited Vulnerabilities catalog on 2026-08-27. In __ip6_append_data()'s paged-allocation branch — taken under MSG_MORE / NETIF_F_SG / large-fraglen conditions — alloclen and pagedlen accounting fail to account for a non-zero "fraggap" carried over from a previous skb once transhdrlen is zero, undersizing the linear allocation while overstating pagedlen, so the fraggap-copy step writes past skb->end into the trailing skb_shared_info. The upstream fix commit states the trigger directly: "an unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES" (Linux kernel stable-tree fix commit, 2026-08-27). The bad accounting was introduced by an earlier commit ("ipv6: avoid partial copy for zc") and only became reachable once a later commit allowed MSG_SPLICE_PAGES to proceed in the negative-copy case that previously returned -EINVAL. CVSS 3.1 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
No public exploitation narrative, named cluster, or affected-distribution list was located beyond the KEV/EUVD listing and the upstream kernel commit itself in this run — this entry treats the flaw as confirmed-exploited per CISA's determination, with the technical mechanism confirmed against the primary kernel-tree commit, but with no further detail available on how it is being exploited or by whom. That gap is itself worth stating plainly rather than filling with inference: a local, unprivileged-to-elevated primitive is meaningfully different from a network-reachable one, and its practical exploitation value depends entirely on an attacker already holding unprivileged local code execution through some other means — which is exactly the scenario a confirmed local kernel LPE turns into full compromise.
Because this affects any Linux kernel exposing an unprivileged user to socket operations — effectively all general-purpose Linux deployments pending distribution backport — the patch lever is the standing kernel-update cycle rather than a configuration change. Triage: none is offered beyond the patch action itself; with no published exploitation narrative, inventing a specific hunting query for this primitive would exceed what the cited sources support. The one available lever short of a distribution backport is restricting which local users or containers can open raw UDPv6 sockets with MSG_SPLICE_PAGES-capable applications, which is not a practical general control for most estates.
An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES.