CVE-2026-53263
Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/06/2026
Última modificación:
08/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
6lowpan: fix off-by-one in multicast context address compression<br />
<br />
The second memcpy in lowpan_iphc_mcast_ctx_addr_compress() uses<br />
&data[1] as destination and &ipaddr->s6_addr[11] as source, but<br />
both should be offset by one: &data[2] and &ipaddr->s6_addr[12]<br />
respectively.<br />
<br />
This off-by-one has two consequences:<br />
1. data[1] is overwritten with s6_addr[11], corrupting the RIID<br />
field in the compressed multicast address<br />
2. data[5] is never written, so uninitialized kernel stack memory<br />
is transmitted over the network via lowpan_push_hc_data(),<br />
leaking kernel stack contents<br />
<br />
The correct inline data layout must match what the decompression<br />
function lowpan_uncompress_multicast_ctx_daddr() expects:<br />
data[0..1] = s6_addr[1..2] (flags/scope + RIID)<br />
data[2..5] = s6_addr[12..15] (group ID)<br />
<br />
Also zero-initialize the data array as a defensive measure against<br />
similar bugs in the future.
Impacto
Puntuación base 3.x
5.50
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.6 (incluyendo) | 5.10.259 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (incluyendo) | 5.15.210 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (incluyendo) | 6.1.176 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (incluyendo) | 6.6.143 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (incluyendo) | 6.12.94 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.36 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.13 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/06ce6fc106b16dec9b535950db626261be865e5b
- https://git.kernel.org/stable/c/2a58899d11009bffc7b4b32a571858f381121837
- https://git.kernel.org/stable/c/4485d79617520d84ba5a14515e2b5136007d6deb
- https://git.kernel.org/stable/c/c32f30ef5e66adbfa102348e2e8a23776eb007cb
- https://git.kernel.org/stable/c/da8808463882c3f3c357b072e25053c2121f1419
- https://git.kernel.org/stable/c/da8cbb64b47e9066b40af0de170901caf17b768c
- https://git.kernel.org/stable/c/dcb1bec1c32ee5c3878354e087cf5dbee2b7c7af
- https://git.kernel.org/stable/c/f24a58c72a45f4c109f3557a760cc4b60b7a6037



