In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()… (CVE-2026-53363)
A critical vulnerability in the Linux kernel's xfrm subsystem was resolved involving the iptfs_consume_frags() function. This function failed to preserve the SKBFL_SHARED_FRAG flag when transferring paged fragments between socket buffers. The missing flag propagation can lead to incorrect handling of shared fragments, affecting the security of in-place encryption decisions in ESP. The issue is similar to a previously fixed bug (CVE-2026-46300) and was addressed by applying the same fix to preserve the shared-frag marker.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel's xfrm subsystem concerns the iptfs_consume_frags() function, which transfers paged fragments from one socket buffer to another but does not propagate the SKBFL_SHARED_FRAG flag. This flag indicates that fragments are shared and backed by read-only page-cache pages, which is critical for the Encapsulating Security Payload (ESP) to determine if in-place encryption is safe. Failure to preserve this flag can lead to incorrect encryption handling. The fix involves applying the same two-line patch previously used in skb_try_coalesce() to ensure the shared-frag marker is preserved during fragment consumption.
Potential Impact
The vulnerability can cause incorrect handling of shared fragments in the Linux kernel's networking stack, potentially leading to improper encryption operations in ESP. This could result in confidentiality, integrity, and availability impacts as indicated by the CVSS vector (Confidentiality: High, Integrity: High, Availability: High). However, no known exploits in the wild have been reported.
Mitigation Recommendations
A fix has been applied to the Linux kernel source code to preserve the SKBFL_SHARED_FRAG flag in iptfs_consume_frags(), similar to the fix for CVE-2026-46300. Users and administrators should update their Linux kernel to a version that includes this fix. Patch status is not explicitly stated in the provided data; therefore, check the official Linux kernel advisories or vendor updates for the exact fixed versions and apply the update accordingly.
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()… (CVE-2026-53363)
Description
A critical vulnerability in the Linux kernel's xfrm subsystem was resolved involving the iptfs_consume_frags() function. This function failed to preserve the SKBFL_SHARED_FRAG flag when transferring paged fragments between socket buffers. The missing flag propagation can lead to incorrect handling of shared fragments, affecting the security of in-place encryption decisions in ESP. The issue is similar to a previously fixed bug (CVE-2026-46300) and was addressed by applying the same fix to preserve the shared-frag marker.
CVSS v3.1
Score 9.8critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel's xfrm subsystem concerns the iptfs_consume_frags() function, which transfers paged fragments from one socket buffer to another but does not propagate the SKBFL_SHARED_FRAG flag. This flag indicates that fragments are shared and backed by read-only page-cache pages, which is critical for the Encapsulating Security Payload (ESP) to determine if in-place encryption is safe. Failure to preserve this flag can lead to incorrect encryption handling. The fix involves applying the same two-line patch previously used in skb_try_coalesce() to ensure the shared-frag marker is preserved during fragment consumption.
Potential Impact
The vulnerability can cause incorrect handling of shared fragments in the Linux kernel's networking stack, potentially leading to improper encryption operations in ESP. This could result in confidentiality, integrity, and availability impacts as indicated by the CVSS vector (Confidentiality: High, Integrity: High, Availability: High). However, no known exploits in the wild have been reported.
Mitigation Recommendations
A fix has been applied to the Linux kernel source code to preserve the SKBFL_SHARED_FRAG flag in iptfs_consume_frags(), similar to the fix for CVE-2026-46300. Users and administrators should update their Linux kernel to a version that includes this fix. Patch status is not explicitly stated in the provided data; therefore, check the official Linux kernel advisories or vendor updates for the exact fixed versions and apply the update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-7xf9-r6gc-x4cm
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53363"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a520ef668715ace4391dd7e
Added to database: 07/11/2026, 09:37:58 UTC
Last enriched: 07/19/2026, 01:23:13 UTC
Last updated: 07/31/2026, 19:24:47 UTC
Views: 57
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.