Cyber Alerts
Linux Kernel Unspecified Vulnerability (CVE-2026-53362)
Several security issues were fixed in the Linux kernel.
- First observed
- 27 Aug 2026
- Last checked
- 07 Sep 2026
- Evidence records
- 4
- Publication state
- Published
What happened?
Current assessment
Several security issues were fixed in the Linux kernel.
Why it matters
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: ARM64 architecture; User-space API (UAPI); Kernel build system; ARM32 architecture; RISC-V architecture; S390 architecture; x86 architecture; Block layer subsystem; Cryptographic API; Compute Acceleration Framework; Intel NPU Driver; ACPI... ACPI drivers; Android drivers; Drivers core; Compressed RAM block device driver; Bluetooth drivers; Character device driver; Hardware random number generator core; CPU frequency scaling framework; Hardware crypto device drivers; Buffer Sharing and Synchronization framework; Intel Stratix 10 firmware drivers; FPGA Framework; GPIO subsystem; GPU drivers; HID subsystem; CoreSight HW tracing drivers; I2C subsystem; IIO subsystem; IIO ADC drivers; InfiniBand drivers; Input Device core drivers; Input Device (Mouse) drivers; IOMMU subsystem; IRQ chip drivers; Multiple devices driver; Media drivers; Multifunction device drivers; Fastrpc Driver; MMC subsystem; Ethernet bonding driver; Network drivers; Mellanox network drivers; MediaTek network drivers; NTB driver; NVME drivers; NVMEM (Non Volatile Memory) drivers; PCI subsystem; Pin controllers subsystem; x86 platform drivers; System reset/shutdown drivers; Power sequencing drivers; PTP clock framework; Voltage and Current Regulator drivers; RPMSG subsystem; SLIMbus drivers; SPI subsystem; Media staging drivers; Realtek RTL8723BS SDIO drivers; VME bus staging drivers; Trusted Execution Environment drivers; Thunderbolt and USB4 drivers; TTY drivers; Cadence USB3 driver; ULPI bus; DesignWare USB3 driver; Faraday FOTG210 USB2 dual-role controller driver; USB Gadget drivers; USB Host Controller drivers; USB ChaosKey driver; Siemens ID Mouse USB driver; IOWarrior USB driver; LD Didactic USB driver; LEGO USB Tower driver; Intel USBIO USB I/O expander driver; USS720 USB parallel port adapter driver; MediaTek USB3 DRD driver; USB Serial drivers; USB Type-C Port Controller Manager driver; USB Type-C Connector System Software Interface driver; USB over IP driver; VFIO drivers; Framebuffer layer; Virtio drivers; BTRFS file system; EROFS file system; exFAT file system; F2FS file system; File systems infrastructure; FUSE (File system in Userspace); GFS2 file system; HFS file system; HFS+ file system; Network file system (NFS) client; Network file system (NFS) server daemon; NILFS2 file system; NTFS3 file system; OCFS2 file system; Proc file system; SMB network file system; UDF file system; XFS file system; Key management; BPF subsystem; Memory management; Software nodes and device properties; Glob pattern matching library; Memory Management; KVM subsystem; Mellanox drivers; Restartable sequences system call mechanism; Socket messages infrastructure; Network traffic control; Bluetooth subsystem; Netfilter; Networking core; Network sockets; TCP network protocol; io_uring subsystem; IPC subsystem; Audit subsystem; Perf events; Kernel fork() syscall; Locking primitives; Kernel module support; Scheduler infrastructure; Signal handling mechanism; Timer subsystem; Tracing infrastructure; Debug objects infrastructure; 6LoWPAN network protocol; IEEE 802 network protocols; 9P file system network protocol; B.A.T.M.A.N. meshing protocol; Ethernet bridge; Devlink API; HSR network protocol; IEEE802154.4 network protocol; IPv4 networking; IPv6 networking; XFRM subsystem; L2TP protocol; MAC80211 subsystem; IEEE 802.15.4 subsystem; Multipath TCP; NetLabel subsystem; Open vSwitch; Phonet protocol; Qualcomm IPC Router (QRTR); RDS protocol; SCTP protocol; SMC sockets; TIPC protocol; TLS protocol; Unix domain sockets; VMware vSockets driver; Wireless networking; eXpress Data Path; AppArmor security module; Linux Security Modules (LSM) Framework; Apple Onboard Audio ALSA driver; ALSA framework; FireWire sound drivers; HD-audio driver; Gravis UltraSound ALSA driver; C-Media CMI8x38 ALSA driver; ESS Solo-1 ALSA driver; ICE1712/ICE1724 (Envy24) ALSA driver; Yamaha YMFPCI ALSA driver; Wolfson Microelectronics audio codecs; SoundWire (SDCA) ASoC drivers; USB sound devices; Virtio sound driver
Who is affected?
Affected products and groups
- Organisation: Linux — Vendor or project named in the CISA KEV catalog.
- Product: Kernel — Product listed by CISA for Linux.
- Software: linux-aws-7.0 on Ubuntu — Package named in the Ubuntu Security Notice.
- Software: linux-aws on Ubuntu — Package named in the Ubuntu Security Notice.
- Software: linux-gcp on Ubuntu — Package named in the Ubuntu Security Notice.
- Software: linux-gke on Ubuntu — Package named in the Ubuntu Security Notice.
- Software: linux-hwe-7.0 on Ubuntu — Package named in the Ubuntu Security Notice.
- Software: linux-oem-7.0 on Ubuntu — Package named in the Ubuntu Security Notice.
- Software: linux-realtime on Ubuntu — Package named in the Ubuntu Security Notice.
- Software: Linux kernel (OEM) on Ubuntu — Software named in USN-8727-1. Consult the notice for affected Ubuntu releases and packages.
- Software: Linux kernel on Ubuntu — Software named in USN-8726-1. Consult the notice for affected Ubuntu releases and packages.
- Software: linux on Ubuntu — Package named in the Ubuntu Security Notice.
What should you do now?
Actions from official guidance
For technical teams
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Official source
- After a standard system update you need to reboot your computer to make all the necessary changes. Official source
- After a standard system update you need to reboot your computer to make all the necessary changes. Official source
- The problem can be corrected by updating your system to the following package versions: Official source
- The problem can be corrected by updating your system to the following package versions: Official source
Which sources support it?
Evidence and official sources
-
Ubuntu Security NoticesOfficial sourceUSN-8727-1: Linux kernel (OEM) vulnerabilities (CVE-2026-53362)
Several security issues were fixed in the Linux kernel.
Published 07 Sep 2026 · Retrieved 07 Sep 2026 -
Ubuntu Security NoticesOfficial sourceUSN-8726-1: Linux kernel vulnerabilities (CVE-2026-53362)
Several security issues were fixed in the Linux kernel.
Published 07 Sep 2026 · Retrieved 07 Sep 2026 -
CISA Known Exploited VulnerabilitiesOfficial sourceLinux Kernel Unspecified Vulnerability (CVE-2026-53362)
Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.
Published 27 Aug 2026 · Retrieved 07 Sep 2026 -
NIST National Vulnerability DatabaseOfficial sourceCVE-2026-53362: In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch …
In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check.
Published 04 Jul 2026 · Retrieved 05 Sep 2026