2026-08-28 · view entry permalink →
Linux kernel IPv6 UDP fraggap accounting bug (CVE-2026-53362) added to CISA KEV, an unprivileged local heap overflow via MSG_SPLICE_PAGES, no exploitation narrative published
CISA added CVE-2026-53362 to its Known Exploited Vulnerabilities catalog on 2026-08-27. In __ip6_append_data()'s paged-allocation branch (taken under MSG_MORE / NETIF_F_SG / large-fraglen conditions) alloclen and pagedlen accounting fail to account for a non-zero "fraggap" carried over from a previous skb once transhdrlen is zero, undersizing the linear allocation while overstating pagedlen, so the fraggap-copy step writes past skb->end into the trailing skb_shared_info. The upstream fix commit states the trigger directly: "an unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES" (Linux kernel stable-tree fix commit, 2026-08-27). The bad accounting was introduced by an earlier commit ("ipv6: avoid partial copy for zc") and only became reachable once a later commit allowed MSG_SPLICE_PAGES to proceed in the negative-copy case that previously returned -EINVAL. CVSS 3.1 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
As of 2026-08-28, no public exploitation narrative, named cluster, or affected-distribution list has been located beyond the KEV/EUVD listing and the upstream kernel commit itself; the flaw is confirmed-exploited per CISA's determination, with the mechanism confirmed against the kernel-tree commit. A local, unprivileged-to-elevated primitive requires an attacker to already hold unprivileged local code execution, exactly the scenario a confirmed kernel LPE turns into full compromise.
Because this affects any Linux kernel exposing an unprivileged user to socket operations (effectively all general-purpose Linux deployments pending distribution backport) the patch lever is the standing kernel-update cycle rather than a configuration change. Triage: none is offered beyond the patch action itself; with no published exploitation narrative, inventing a specific hunting query for this primitive would exceed what the cited sources support. The one available lever short of a distribution backport is restricting which local users or containers can open raw UDPv6 sockets with MSG_SPLICE_PAGES-capable applications, which is not a practical general control for most estates.
An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES.
This CVE was recorded as pre-auth, which contradicts the CVSS vector the entry itself quotes: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, score 7.8. PR:L means the attacker must already hold an unprivileged local account, and the trigger is a local user opening a UDPv6 socket with MSG_MORE and MSG_SPLICE_PAGES set together (upstream kernel fix commit 14200d43). It is a local privilege-escalation primitive, not a remotely reachable one. For scoping, that puts the exposure on hosts where untrusted code already runs, containers, shared shells, CI runners and multi-tenant systems, rather than on the network perimeter.