CVE-2026-53263

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/06/2026
Last modified:
08/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> 6lowpan: fix off-by-one in multicast context address compression<br /> <br /> The second memcpy in lowpan_iphc_mcast_ctx_addr_compress() uses<br /> &amp;data[1] as destination and &amp;ipaddr-&gt;s6_addr[11] as source, but<br /> both should be offset by one: &amp;data[2] and &amp;ipaddr-&gt;s6_addr[12]<br /> respectively.<br /> <br /> This off-by-one has two consequences:<br /> 1. data[1] is overwritten with s6_addr[11], corrupting the RIID<br /> field in the compressed multicast address<br /> 2. data[5] is never written, so uninitialized kernel stack memory<br /> is transmitted over the network via lowpan_push_hc_data(),<br /> leaking kernel stack contents<br /> <br /> The correct inline data layout must match what the decompression<br /> function lowpan_uncompress_multicast_ctx_daddr() expects:<br /> data[0..1] = s6_addr[1..2] (flags/scope + RIID)<br /> data[2..5] = s6_addr[12..15] (group ID)<br /> <br /> Also zero-initialize the data array as a defensive measure against<br /> similar bugs in the future.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.6 (including) 5.10.259 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.210 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.176 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.143 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.94 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.36 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.13 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*