PT-2026-51968 · Linux+2 · Linux Kernel+2
CVE-2026-53074
·
Published
2026-04-12
·
Updated
2026-09-07
CVSS v2.0
5.9
Medium
| Vector | AV:L/AC:H/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
bpf prog test run skb() function where the system may access ip hdr(skb) or ipv6 hdr(skb) even if the provided test input contains only an Ethernet header. This occurs because the function calls eth type trans() and uses skb->protocol to initialize family and address fields without first verifying if the Layer 3 (L3) header is sufficiently long for IPv4 or IPv6 packets.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu