PT-2026-52344 · Linux+1 · Linux Kernel+1

CVE-2026-53249

·

Published

2026-06-03

·

Updated

2026-09-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description Unprivileged applications can set Loose Source and Record Route (LSRR) and Strict Source and Record Route (SSRR) IP options. This allows an attacker to force packets to route through controlled nodes, potentially leaking the TCP Initial Sequence Number (ISN) and other protocol information. The issue involves the IPOPT SSRR and IPOPT LSRR options.
Recommendations Restrict the ability to set IPOPT SSRR and IPOPT LSRR options to users with the CAP NET RAW capability.

Exploit

Fix

Improper Access Control

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90642
BDU:2026-14062
CVE-2026-53249
ECHO-F3E9-0D38-A036
OESA-2026-2930
OESA-2026-3204
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22809-1
SUSE-SU-2026:22810-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:22903-1
SUSE-SU-2026:22904-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
SUSE-SU-2026:3594-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu