PT-2026-52323 · Linux+2 · Linux Kernel+2

CVE-2026-53228

·

Published

2026-06-08

·

Updated

2026-09-07

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the SIT (Simple Internet Tunneling) implementation for IPv6. The ipip6 tunnel xmit() function caches the inner IPv6 header pointer at the start of the function and continues to use it after calling iptunnel handle offloads(). For GSO (Generic Segmentation Offload) skbs, iptunnel handle offloads() invokes skb header unclone(), which may call pskb expand head(). This process can move the skb head, rendering existing pointers stale. If the skb realloc headroom() branch is not taken, the system uses a stale iph6 pointer to read the inner hop limit and DS field, potentially leading to a read from a freed skb head after the old head's remaining clone is released.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90734
BDU:2026-14052
CVE-2026-53228
ECHO-719C-235F-D114
OESA-2026-3204
USN-8629-1
USN-8629-2
USN-8629-3
USN-8630-1
USN-8630-2
USN-8630-3
USN-8630-4
USN-8630-5
USN-8631-1
USN-8631-2
USN-8631-3
USN-8631-4
USN-8633-1
USN-8633-2
USN-8635-1
USN-8636-1
USN-8636-2
USN-8637-1
USN-8645-1
USN-8656-1
USN-8660-1
USN-8661-1
USN-8661-2
USN-8661-3
USN-8661-4
USN-8662-1
USN-8662-2
USN-8663-1
USN-8664-1
USN-8666-1
USN-8666-2
USN-8666-3
USN-8667-1
USN-8669-1
USN-8715-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu