Linux kernel IPv6 UDP fraggap accounting bug (CVE-2026-53362) added to CISA KEV, an unprivileged local heap overflow via MSG_SPLICE_PAGES, no exploitation narrative published
A confirmed-exploited Linux kernel local privilege-escalation primitive with no public account of how it is being used
Defender actions
- Apply the distribution kernel update carrying this stable-tree fix as soon as it is available for every running Linux distribution; CISA's KEV listing confirms active exploitation, and there is no practical configuration-level workaround short of restricting untrusted local users' ability to open raw UDPv6 sockets with MSG_SPLICE_PAGES-capable applications.
Analysis
CISA added CVE-2026-53362 to its Known Exploited Vulnerabilities catalog on 2026-08-27. In __ip6_append_data()'s paged-allocation branch (taken under MSG_MORE / NETIF_F_SG / large-fraglen conditions) alloclen and pagedlen accounting fail to account for a non-zero "fraggap" carried over from a previous skb once transhdrlen is zero, undersizing the linear allocation while overstating pagedlen, so the fraggap-copy step writes past skb->end into the trailing skb_shared_info. The upstream fix commit states the trigger directly: "an unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES" (Linux kernel stable-tree fix commit, 2026-08-27). The bad accounting was introduced by an earlier commit ("ipv6: avoid partial copy for zc") and only became reachable once a later commit allowed MSG_SPLICE_PAGES to proceed in the negative-copy case that previously returned -EINVAL. CVSS 3.1 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
As of 2026-08-28, no public exploitation narrative, named cluster, or affected-distribution list has been located beyond the KEV/EUVD listing and the upstream kernel commit itself; the flaw is confirmed-exploited per CISA's determination, with the mechanism confirmed against the kernel-tree commit. A local, unprivileged-to-elevated primitive requires an attacker to already hold unprivileged local code execution, exactly the scenario a confirmed kernel LPE turns into full compromise.
Because this affects any Linux kernel exposing an unprivileged user to socket operations (effectively all general-purpose Linux deployments pending distribution backport) the patch lever is the standing kernel-update cycle rather than a configuration change. Triage: none is offered beyond the patch action itself; with no published exploitation narrative, inventing a specific hunting query for this primitive would exceed what the cited sources support. The one available lever short of a distribution backport is restricting which local users or containers can open raw UDPv6 sockets with MSG_SPLICE_PAGES-capable applications, which is not a practical general control for most estates.
Cited evidence
An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES.
Updates1
This CVE was recorded as pre-auth, which contradicts the CVSS vector the entry itself quotes: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, score 7.8. PR:L means the attacker must already hold an unprivileged local account, and the trigger is a local user opening a UDPv6 socket with MSG_MORE and MSG_SPLICE_PAGES set together (upstream kernel fix commit 14200d43). It is a local privilege-escalation primitive, not a remotely reachable one. For scoping, that puts the exposure on hosts where untrusted code already runs, containers, shared shells, CI runners and multi-tenant systems, rather than on the network perimeter.
Sources2
Revision history
- Published 2026-08-28T0409Z-intel
- Correction 2026-08-30T1312Z-audit
The CVE record said pre-auth while the entry's own quoted CVSS vector says otherwise. The vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H: local attack vector, low privileges required, meaning an unprivileged local user who can already open a UDPv6 socket, not an unauthenticated actor. Corrected to post-auth. This narrows who can reach the flaw but not its severity: the KEV listing and the local privilege-escalation impact are unchanged, and on a multi-tenant or shell-accessible host the prerequisite is trivially met.
Changed: cves sourcing_note body
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.