PT-2026-52318 · Linux+2 · Linux Kernel+2
CVE-2026-53223
·
Published
2026-06-25
·
Updated
2026-09-09
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the network subsystem where the
skb is err queue() function incorrectly identifies AF PACKET sockets as error-queue skbs because it relies solely on the PACKET OUTGOING marker. When timestamping is enabled and SO RXQ OVFL is active, the system may misinterpret AF PACKET control-buffer state as sock exterr skb::opt stats. If the packet drop counter is odd, the path emits SCM TIMESTAMPING OPT STATS using skb->len and skb->data. For non-linear skbs, this process can copy data beyond the linear head, potentially triggering hardened usercopy or disclosing adjacent heap contents.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu