Red Hat Security Advisory: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: kernel: ipv6 frag escape () For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the NVIDIA for RHEL 10 Release Notes linked from the References section.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel IPv6 code occurs in the __ip6_append_data() function when handling paged allocation with MSG_MORE and MSG_SPLICE_PAGES flags on UDPv6 sockets. Incorrect calculation of allocation length and paged length due to unaccounted fragment gap (fraggap) bytes leads to an undersized linear buffer and an overstated paged length, causing a buffer overflow that writes beyond the skb linear area into skb_shared_info. This flaw allows an unprivileged user to trigger memory corruption. The issue was introduced by a commit that allowed MSG_SPLICE_PAGES to proceed despite negative copy values, which previously returned an error. The fix involves adjusting alloclen and pagedlen calculations to include fraggap correctly and removing obsolete negative copy checks.
Potential Impact
The vulnerability allows an unprivileged user to cause a buffer overflow in kernel memory by sending specially crafted UDPv6 packets with MSG_MORE and MSG_SPLICE_PAGES flags. This can lead to memory corruption with potential consequences including denial of service, privilege escalation, or arbitrary code execution in the kernel context. The CVSS vector indicates low attack complexity and privileges required, with high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official patch links are provided in the input data. Until a patch is available, avoid using UDPv6 sockets with MSG_MORE and MSG_SPLICE_PAGES flags in untrusted environments to reduce risk.
Red Hat Security Advisory: kernel security update
Description
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: kernel: ipv6 frag escape () For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the NVIDIA for RHEL 10 Release Notes linked from the References section.
CVSS v3.1
Score 7.8high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel IPv6 code occurs in the __ip6_append_data() function when handling paged allocation with MSG_MORE and MSG_SPLICE_PAGES flags on UDPv6 sockets. Incorrect calculation of allocation length and paged length due to unaccounted fragment gap (fraggap) bytes leads to an undersized linear buffer and an overstated paged length, causing a buffer overflow that writes beyond the skb linear area into skb_shared_info. This flaw allows an unprivileged user to trigger memory corruption. The issue was introduced by a commit that allowed MSG_SPLICE_PAGES to proceed despite negative copy values, which previously returned an error. The fix involves adjusting alloclen and pagedlen calculations to include fraggap correctly and removing obsolete negative copy checks.
Potential Impact
The vulnerability allows an unprivileged user to cause a buffer overflow in kernel memory by sending specially crafted UDPv6 packets with MSG_MORE and MSG_SPLICE_PAGES flags. This can lead to memory corruption with potential consequences including denial of service, privilege escalation, or arbitrary code execution in the kernel context. The CVSS vector indicates low attack complexity and privileges required, with high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official patch links are provided in the input data. Until a patch is available, avoid using UDPv6 sockets with MSG_MORE and MSG_SPLICE_PAGES flags in untrusted environments to reduce risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3x6f-vm7x-cgm7
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53362"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a498a7327e9c7971936e8da
Added to database: 07/04/2026, 22:34:27 UTC
Last enriched: 07/19/2026, 01:23:27 UTC
Last updated: 07/31/2026, 20:00:14 UTC
Views: 232
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.