PT-2026-52318 · Linux+2 · Linux Kernel+2

CVE-2026-53223

·

Published

2026-06-25

·

Updated

2026-09-09

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the network subsystem where the skb is err queue() function incorrectly identifies AF PACKET sockets as error-queue skbs because it relies solely on the PACKET OUTGOING marker. When timestamping is enabled and SO RXQ OVFL is active, the system may misinterpret AF PACKET control-buffer state as sock exterr skb::opt stats. If the packet drop counter is odd, the path emits SCM TIMESTAMPING OPT STATS using skb->len and skb->data. For non-linear skbs, this process can copy data beyond the linear head, potentially triggering hardened usercopy or disclosing adjacent heap contents.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:66180
CVE-2026-53223
ECHO-9894-6513-179B
OESA-2026-3204
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu