Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 82%

Red Hat Security Advisory: kernel security update

0
High
Published: 07/02/2026 (07/02/2026, 13:21:17 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: kernel: ipv6 frag escape () For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the NVIDIA for RHEL 10 Release Notes linked from the References section.

CVSS v3.1

Score 7.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

Affected versions
Red HatRed Hat Enterprise Linux for NVIDIANVIDIA for RHEL 10srckernel-0:6.12.0-231.14.el10nv.src

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/19/2026, 01:23:27 UTC

Technical Analysis

The vulnerability in the Linux kernel IPv6 code occurs in the __ip6_append_data() function when handling paged allocation with MSG_MORE and MSG_SPLICE_PAGES flags on UDPv6 sockets. Incorrect calculation of allocation length and paged length due to unaccounted fragment gap (fraggap) bytes leads to an undersized linear buffer and an overstated paged length, causing a buffer overflow that writes beyond the skb linear area into skb_shared_info. This flaw allows an unprivileged user to trigger memory corruption. The issue was introduced by a commit that allowed MSG_SPLICE_PAGES to proceed despite negative copy values, which previously returned an error. The fix involves adjusting alloclen and pagedlen calculations to include fraggap correctly and removing obsolete negative copy checks.

Potential Impact

The vulnerability allows an unprivileged user to cause a buffer overflow in kernel memory by sending specially crafted UDPv6 packets with MSG_MORE and MSG_SPLICE_PAGES flags. This can lead to memory corruption with potential consequences including denial of service, privilege escalation, or arbitrary code execution in the kernel context. The CVSS vector indicates low attack complexity and privileges required, with high impact on confidentiality, integrity, and availability.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official patch links are provided in the input data. Until a patch is available, avoid using UDPv6 sockets with MSG_MORE and MSG_SPLICE_PAGES flags in untrusted environments to reduce risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-3x6f-vm7x-cgm7
Osv Schema Version
1.4.0
Aliases
["CVE-2026-53362"]
Ecosystems
[]
Database Specific Severity
null
Cvss Version
3.1

Threat ID: 6a498a7327e9c7971936e8da

Added to database: 07/04/2026, 22:34:27 UTC

Last enriched: 07/19/2026, 01:23:27 UTC

Last updated: 07/31/2026, 20:00:14 UTC

Views: 232

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses