CVE-2026-53151

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/06/2026
Last modified:
06/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> rxrpc: Fix the ACK parser to extract the SACK table for parsing<br /> <br /> Fix modification of the received skbuff in rxrpc_input_soft_acks() and a<br /> potential incorrect access of the buffer in a fragmented UDP packet (the<br /> packet would probably have to be deliberately pre-generated as fragmented)<br /> when AF_RXRPC tries to extract the contents of the SACK table by copying<br /> out the contents of the SACK table into a buffer before attempting to parse<br /> <br /> AF_RXRPC assumes that it can just call skb_condense() and then validly<br /> access the SACK table from skb-&gt;data and that it will be a flat buffer -<br /> but skb_condense() can silently fail to do anything under some<br /> circumstances.<br /> <br /> Note that whilst rxrpc_input_soft_acks() should be able to parse extended<br /> ACKs, the rest of AF_RXRPC doesn&amp;#39;t currently support that.<br /> <br /> Further, there&amp;#39;s then no need to call skb_condense() in rxrpc_input_ack(),<br /> so don&amp;#39;t.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.144 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.95 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.36 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.13 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*