boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-53362

Linux Linux — ipv6: account for fraggap on the paged allocation path
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0071   51.9   YES
AFFECTED
  Product  Versions                                    Fixed
  Linux    773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 –  —
  Linux    6.0 –                                       6.1.177
TIMELINE
  Jun 9   Reserved by Linux
  Jul 4   Published (CNA: Linux)
  Aug 27  ADDED TO KEV — CVE-2026-53362 (Linux). Remediation due August 30, 2026.
  Aug 31  DUE DATE PASSED — CVE-2026-53362 (Linux). CISA remediation deadline was August 30, 2026; still in catalog.
CWE-787, CWE-122 · CNA: Linux · CVSS v3.1 · 7 references · NVD status: Analyzed · KEV due August 30, 2026

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
June 9, 2026ReservedReserved by Linux
July 4, 2026PublishedPublished (CNA: Linux)
August 27, 2026KEV ADDEDADDED TO KEV — CVE-2026-53362 (Linux). Remediation due August 30, 2026.
August 31, 2026DUE DATE PASSEDDUE DATE PASSED — CVE-2026-53362 (Linux). CISA remediation deadline was August 30, 2026; still in catalog.

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
LinuxLinux—773ba4fe9104a64a54d1c00f0fb6ffb95def2b03—
LinuxLinux—6.06.1.177

Weaknesses

CWE-787 · CWE-122

References (7)

Related

Authoritative record: CVE-2026-53362 at cve.org

Vendors: linux

Weaknesses: CWE-787 · CWE-122

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-53362 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.