Skip to main content
QUIETLYTIC
Vulnerability

Linux Kernel Vulnerability (CVE-2026-53362)

CVE-2026-53362 is a CVSS 7.8 Linux kernel memory-corruption flaw in IPv6 UDP fragment handling, confirmed exploited per CISA KEV.

CVE-2026-53362
Threat Level
HIGH
CVSS
7.8
Status
Active Exploitation
Confidence
High
Affected Products
Linux Kernel

CVE-2026-53362 carries a CVSS 3.1 base score of 7.8 against the Linux kernel. NVD classifies it under CWE-787 (Out-of-Bounds Write) and CWE-122 (Heap-Based Buffer Overflow). CISA added this CVE to its Known Exploited Vulnerabilities catalog on August 27, 2026, confirming real-world exploitation directly rather than through a single vendor report; VulnCheck’s KEV feed independently corroborates the same exploitation status and date.

Because CISA KEV itself is the authoritative source for exploitation status, this CVE carries high confidence on that point. CISA KEV listing also means the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies, per CISA’s own mitigation guidance in our source data.

What the flaw is

NVD’s description, sourced from the upstream kernel fix commit, locates the bug in the kernel’s IPv6 output path for UDP packets that are built up across multiple send calls using a scatter-gather/zero-copy technique. NVD states an accounting error in how the kernel calculates buffer sizes for the paged-allocation branch of that path caused it to undersize the packet’s linear buffer while oversizing its paged portion by the same amount, so data belonging to a carried-over fragment gap is written past the end of the allocated buffer into adjacent kernel memory. NVD states an unprivileged local user can reach this code path through an ordinary IPv6 UDP socket using standard kernel socket options, without requiring elevated privileges.

We are reporting the nature of the accounting error and its consequence — a heap buffer overflow reachable by an unprivileged local user — rather than the exact sequence of socket calls involved, which is available in the upstream kernel commit NVD cites for readers who need it for patch verification.

Evidence and confidence

  • High confidence — exploitation status, corroborated independently by CISA KEV and VulnCheck KEV, both dated August 27, 2026.
  • Medium confidence — the CVSS 7.8 score and vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), and the CWE-787/CWE-122 classification, which trace to NVD alone in our current ingestion, corroborated by the upstream kernel fix commits NVD links.
  • Moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.0051, a 42.3rd percentile score as of our ingestion.

No field is in conflict between our sources. Our data carries no single fixed-version field; the upstream kernel commits NVD links identify the corrected code across multiple stable kernel branches.

Why this matters

This vulnerability’s CVSS vector marks it local (AV:L) with low privileges required (PR:L) — meaning it’s not remotely reachable in itself, but is well-suited as a privilege-escalation or sandbox-escape step for an attacker who has already obtained limited local code execution on a Linux host, a common second stage in a broader intrusion. Kernel memory-corruption bugs of this class are frequently used to break out of containers or unprivileged process sandboxes precisely because they only require ordinary local socket access, not elevated credentials, and this one’s confirmed exploitation status via CISA KEV suggests it is already being used that way somewhere in the wild.

Frequently Asked Questions

What is CVE-2026-53362? A CVSS 7.8 heap buffer overflow (CWE-787/CWE-122) in the Linux kernel’s IPv6 UDP output path, caused by a buffer-size accounting error that lets an unprivileged local user corrupt adjacent kernel memory via an ordinary IPv6 UDP socket.

Is CVE-2026-53362 being actively exploited? Yes, per two independent sources: CISA’s Known Exploited Vulnerabilities catalog and VulnCheck’s KEV feed, both dated August 27, 2026.

Do I need remote network access to exploit this? No. The CVSS vector specifies a local attack vector requiring low privileges — this is exploitable by a local unprivileged user, not remotely over the network.

Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.

Which kernel versions fix this? Our source data carries no single fixed-version field. Consult the upstream kernel fix commits linked from NVD’s record for the specific stable-branch versions that include the fix.


Severity, weakness classification, and mechanism sourced from the National Vulnerability Database record for CVE-2026-53362 and the linked upstream Linux kernel fix commit. Exploitation status and the August 27, 2026 catalog date sourced from CISA’s Known Exploited Vulnerabilities catalog entry, independently corroborated by VulnCheck KEV. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog
03 VulnCheck KEV

Related intelligence


Analyst tools