PT-2026-52271 · Linux+2 · Linux Kernel+2

CVE-2026-53175

·

Published

2026-06-04

·

Updated

2026-09-10

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists during network namespace teardown. The function fqdir pre exit() flushes incomplete fragment queues via inet frag queue flush(), which frees queued socket buffers (skbs) but fails to clear the fragments tail and last run head pointers. If a fragment previously obtained through inet frag find() resumes execution and acquires the queue lock after this flush, it may dereference the freed fragments tail. Subsequently, inet frag queue insert() reads and writes to these freed pointers, leading to a slab use-after-free. This issue also affects IPv6, nf conntrack reasm6, and 6lowpan reassembly.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14019
CVE-2026-53175
OESA-2026-3204
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1
USN-8629-1
USN-8629-2
USN-8629-3
USN-8637-1
USN-8660-1
USN-8663-1
USN-8664-1
USN-8728-1
USN-8748-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu