CTIPilot
← Back to Daily brief 2026-08-28
NOTABLECVE-2026-53362exploitedupdatedNATOA2vulnerability

Linux kernel IPv6 UDP fraggap accounting bug (CVE-2026-53362) added to CISA KEV, an unprivileged local heap overflow via MSG_SPLICE_PAGES, no exploitation narrative published

A confirmed-exploited Linux kernel local privilege-escalation primitive with no public account of how it is being used

Defender actions

  • Apply the distribution kernel update carrying this stable-tree fix as soon as it is available for every running Linux distribution; CISA's KEV listing confirms active exploitation, and there is no practical configuration-level workaround short of restricting untrusted local users' ability to open raw UDPv6 sockets with MSG_SPLICE_PAGES-capable applications.

Analysis

CISA added CVE-2026-53362 to its Known Exploited Vulnerabilities catalog on 2026-08-27. In __ip6_append_data()'s paged-allocation branch (taken under MSG_MORE / NETIF_F_SG / large-fraglen conditions) alloclen and pagedlen accounting fail to account for a non-zero "fraggap" carried over from a previous skb once transhdrlen is zero, undersizing the linear allocation while overstating pagedlen, so the fraggap-copy step writes past skb->end into the trailing skb_shared_info. The upstream fix commit states the trigger directly: "an unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES" (Linux kernel stable-tree fix commit, 2026-08-27). The bad accounting was introduced by an earlier commit ("ipv6: avoid partial copy for zc") and only became reachable once a later commit allowed MSG_SPLICE_PAGES to proceed in the negative-copy case that previously returned -EINVAL. CVSS 3.1 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

As of 2026-08-28, no public exploitation narrative, named cluster, or affected-distribution list has been located beyond the KEV/EUVD listing and the upstream kernel commit itself; the flaw is confirmed-exploited per CISA's determination, with the mechanism confirmed against the kernel-tree commit. A local, unprivileged-to-elevated primitive requires an attacker to already hold unprivileged local code execution, exactly the scenario a confirmed kernel LPE turns into full compromise.

Because this affects any Linux kernel exposing an unprivileged user to socket operations (effectively all general-purpose Linux deployments pending distribution backport) the patch lever is the standing kernel-update cycle rather than a configuration change. Triage: none is offered beyond the patch action itself; with no published exploitation narrative, inventing a specific hunting query for this primitive would exceed what the cited sources support. The one available lever short of a distribution backport is restricting which local users or containers can open raw UDPv6 sockets with MSG_SPLICE_PAGES-capable applications, which is not a practical general control for most estates.

Cited evidence

An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES.

Linux kernel stable tree (upstream fix commit) 2026-08-27

Updates1

Correction

This CVE was recorded as pre-auth, which contradicts the CVSS vector the entry itself quotes: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, score 7.8. PR:L means the attacker must already hold an unprivileged local account, and the trigger is a local user opening a UDPv6 socket with MSG_MORE and MSG_SPLICE_PAGES set together (upstream kernel fix commit 14200d43). It is a local privilege-escalation primitive, not a remotely reachable one. For scoping, that puts the exposure on hosts where untrusted code already runs, containers, shared shells, CI runners and multi-tenant systems, rather than on the network perimeter.

Sources2

Revision history

  1. Published 2026-08-28T0409Z-intel
  2. Correction 2026-08-30T1312Z-audit

    The CVE record said pre-auth while the entry's own quoted CVSS vector says otherwise. The vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H: local attack vector, low privileges required, meaning an unprivileged local user who can already open a UDPv6 socket, not an unauthenticated actor. Corrected to post-auth. This narrows who can reach the flaw but not its severity: the KEV listing and the local privilege-escalation impact are unchanged, and on a multi-tenant or shell-accessible host the prerequisite is trivially met.

    Changed: cves sourcing_note body

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.