Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-53362
Linux Linux — ipv6: account for fraggap on the paged allocation path
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0071 51.9 YES
AFFECTED
Product Versions Fixed
Linux 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – —
Linux 6.0 – 6.1.177
TIMELINE
Jun 9 Reserved by Linux
Jul 4 Published (CNA: Linux)
Aug 27 ADDED TO KEV — CVE-2026-53362 (Linux). Remediation due August 30, 2026.
Aug 31 DUE DATE PASSED — CVE-2026-53362 (Linux). CISA remediation deadline was August 30, 2026; still in catalog.
Description
In the Linux kernel, the following vulnerability has been resolved:
ipv6: account for fraggap on the paged allocation path
In __ip6_append_data(), when the paged-allocation branch is taken
(MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are
computed as
alloclen = fragheaderlen + transhdrlen;
pagedlen = datalen - transhdrlen;
datalen already includes fraggap (datalen = length + fraggap). When
fraggap is non-zero, this is not the first skb and transhdrlen is zero.
The fraggap bytes carried over from the previous skb are copied just past
the fragment headers in the new skb's linear area. The linear area is
therefore undersized by fraggap bytes while pagedlen is overstated by the
same amount, and the copy writes past skb->end into the trailing
skb_shared_info.
An unprivileged user can trigger this via a UDPv6 socket using
MSG_MORE together with MSG_SPLICE_PAGES.
The bad accounting was introduced by commit 773ba4fe9104 ("ipv6:
avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix
__ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative
copy value caused -EINVAL to be returned. That later commit allowed
MSG_SPLICE_PAGES to proceed in this case, making the corruption
triggerable.
The non-paged branch sets alloclen to fraglen, which already accounts
for fraggap because datalen does. Bring the paged branch in line by
adding fraggap to alloclen and subtracting it from pagedlen.
After this adjustment, copy no longer collapses to -fraggap on the
paged path, so remove the stale comment describing that old arithmetic.
Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES
case, remove the MSG_SPLICE_PAGES exception from the negative copy check.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| June 9, 2026 | Reserved | Reserved by Linux |
| July 4, 2026 | Published | Published (CNA: Linux) |
| August 27, 2026 | KEV ADDED | ADDED TO KEV — CVE-2026-53362 (Linux). Remediation due August 30, 2026. |
| August 31, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2026-53362 (Linux). CISA remediation deadline was August 30, 2026; still in catalog. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 | — |
| Linux | Linux | — | 6.0 | 6.1.177 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-53362 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.