A vulnerability in the Linux kernel related to IPv4 IP options Loose Source and Record Route (LSRR) and Strict Source and Record Route (SSRR) has… (CVE-2026-53249)
A vulnerability in the Linux kernel related to IPv4 IP options Loose Source and Record Route (LSRR) and Strict Source and Record Route (SSRR) has been addressed. The patch restricts setting these IP options to users with CAP_NET_RAW capability, preventing unprivileged applications from manipulating packet routing to potentially leak TCP Initial Sequence Numbers (ISN) and other protocol information. Although many networks filter these options, some paths may still forward them. RFC 7126 recommends dropping such IPv4 options to mitigate risks.
AI Analysis
Technical Summary
The Linux kernel vulnerability involves insufficient restriction on setting the IPv4 IP options LSRR and SSRR. Previously, unprivileged users could set these options, allowing packets to be routed through attacker-controlled nodes, potentially leaking TCP ISN and other protocol data. The patch enforces that only users with CAP_NET_RAW capability can set these options, reducing the attack surface. This aligns with RFC 7126 recommendations to filter or drop packets containing these options.
Potential Impact
Unprivileged users could exploit this vulnerability to force packets through attacker-controlled nodes, enabling leakage of TCP Initial Sequence Numbers and possibly other protocol information. This could undermine protocol security and potentially facilitate further attacks. The vulnerability does not impact confidentiality or integrity directly but affects availability with a high impact rating in CVSS (A:H).
Mitigation Recommendations
A patch has been applied to the Linux kernel restricting the use of LSRR and SSRR IP options to privileged users with CAP_NET_RAW capability. Users should ensure their Linux kernel is updated to a version including this fix. Since this is a kernel-level fix, updating the kernel is the recommended remediation. No additional mitigation is indicated by the vendor advisory.
A vulnerability in the Linux kernel related to IPv4 IP options Loose Source and Record Route (LSRR) and Strict Source and Record Route (SSRR) has… (CVE-2026-53249)
Description
A vulnerability in the Linux kernel related to IPv4 IP options Loose Source and Record Route (LSRR) and Strict Source and Record Route (SSRR) has been addressed. The patch restricts setting these IP options to users with CAP_NET_RAW capability, preventing unprivileged applications from manipulating packet routing to potentially leak TCP Initial Sequence Numbers (ISN) and other protocol information. Although many networks filter these options, some paths may still forward them. RFC 7126 recommends dropping such IPv4 options to mitigate risks.
CVSS v3.1
Score 5.5medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability involves insufficient restriction on setting the IPv4 IP options LSRR and SSRR. Previously, unprivileged users could set these options, allowing packets to be routed through attacker-controlled nodes, potentially leaking TCP ISN and other protocol data. The patch enforces that only users with CAP_NET_RAW capability can set these options, reducing the attack surface. This aligns with RFC 7126 recommendations to filter or drop packets containing these options.
Potential Impact
Unprivileged users could exploit this vulnerability to force packets through attacker-controlled nodes, enabling leakage of TCP Initial Sequence Numbers and possibly other protocol information. This could undermine protocol security and potentially facilitate further attacks. The vulnerability does not impact confidentiality or integrity directly but affects availability with a high impact rating in CVSS (A:H).
Mitigation Recommendations
A patch has been applied to the Linux kernel restricting the use of LSRR and SSRR IP options to privileged users with CAP_NET_RAW capability. Users should ensure their Linux kernel is updated to a version including this fix. Since this is a kernel-level fix, updating the kernel is the recommended remediation. No additional mitigation is indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-r3wj-w7v3-6mqq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53249"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a4e4ee2c9d9e3dbe3289550
Added to database: 07/08/2026, 13:21:38 UTC
Last enriched: 07/08/2026, 13:37:10 UTC
Last updated: 07/31/2026, 19:24:47 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.