CVE-2026-53228
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/06/2026
Last modified:
02/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ipv6: sit: reload inner IPv6 header after GSO offloads<br />
<br />
ipip6_tunnel_xmit() caches the inner IPv6 header pointer at function<br />
entry and continues using it after iptunnel_handle_offloads().<br />
<br />
For GSO skbs, iptunnel_handle_offloads() calls skb_header_unclone().<br />
When the skb header is cloned, skb_header_unclone() can call<br />
pskb_expand_head(), which may move the skb head. The pskb_expand_head()<br />
contract requires pointers into the skb header to be reloaded after the<br />
call.<br />
<br />
If the later skb_realloc_headroom() branch is not taken, SIT uses the<br />
stale iph6 pointer to read the inner hop limit and DS field. That can<br />
read from a freed skb head after the old head&#39;s remaining clone is<br />
released.<br />
<br />
Reload iph6 after the offload helper succeeds and before subsequent<br />
reads from the inner IPv6 header. Keep the existing reload after<br />
skb_realloc_headroom(), since that branch can also replace the skb.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 3.18 (including) | 5.10.259 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.210 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.176 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.143 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.94 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.36 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.13 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0bfa7bba1f41aaf5f0604dc712bb4701493e3aa0
- https://git.kernel.org/stable/c/1132e5edc2866c3530be17622153a597095f0e43
- https://git.kernel.org/stable/c/2fa49b2715e1bad12ce3b0fa64e234d9582c8193
- https://git.kernel.org/stable/c/59f80c919713250fe5d25a4d9aea4e49580fa1d4
- https://git.kernel.org/stable/c/9c67b44edb3598d234efae6e44649eb993c03da5
- https://git.kernel.org/stable/c/cb658c2f5f7977c2a1c77c9f239f4bc8196edb5c
- https://git.kernel.org/stable/c/f0e42f0c4337b1f220de1ddd63f47197c7dee4de
- https://git.kernel.org/stable/c/fddd41445a0537b093e6b3f6232c9933cad1e48b



