DIRAS TAKE
Urgent — CISA placed CVE-2026-53362 on the Known Exploited Vulnerabilities catalog with a remediation deadline of 2026-08-30; apply available fixes or vendor mitigations immediately.
What is CVE-2026-53362?
A local, unprivileged user can cause out-of-bounds memory writes in the Linux kernel's IPv6 packet assembly code and gain elevated privileges; this is tracked as CVE-2026-53362. The bug affects multiple kernel branches including 14200.x, 65.x, 46.x, 6374.x, mainline Linux, 736.x, and is listed for 6.0 without a fixed commit. Exploitation is performed from the host by sending specially crafted UDPv6 traffic that uses MSG_MORE together with MSG_SPLICE_PAGES to trigger incorrect length accounting during paged allocation. The weakness is classified as CWE-787 (Out-of-bounds Write).
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Linux Kernel are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 14200.x | 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – before 14200d435af9a9eeb444f529fc2f689a236b7962 | 14200d435af9a9eeb444f529fc2f689a236b7962 |
| 65.x | 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – before 65fb14cbebb0cd0eff903a22d33537ddc8b95769 | 65fb14cbebb0cd0eff903a22d33537ddc8b95769 |
| 46.x | 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – before 46f201f8b4c39633a1fa3dc12459f506d470993d | 46f201f8b4c39633a1fa3dc12459f506d470993d |
| 6374.x | 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – before 6374fb9edf72c67a118a2c214a0dddd04c921e0a | 6374fb9edf72c67a118a2c214a0dddd04c921e0a |
| Linux | 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – before e9eacf19281ea2498b36291b56c9606118c2d74e | e9eacf19281ea2498b36291b56c9606118c2d74e |
| 736.x | 773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – before 736b380e28d0480c7bc3e022f1950f31fe53a7c5 | 736b380e28d0480c7bc3e022f1950f31fe53a7c5 |
| 6.x | 6.0 |
Is CVE-2026-53362 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-08-27, and US federal agencies are required to remediate by 2026-08-30. Public exploit code is available.
How to fix CVE-2026-53362
- Upgrade the kernel to the fixed commits for your branch (examples: 14200 → 14200d435af9a9eeb444f529fc2f689a236b7962, 65.x → 65fb14cbebb0cd0eff903a22d33537ddc8b95769, 46.x → 46f201f8b4c39633a1fa3dc12459f506d470993d, 6374.x → 6374fb9edf72c67a118a2c214a0dddd04c921e0a, mainline → e9eacf19281ea2498b36291b56c9606118c2d74e, 736.x → 736b380e28d0480c7bc3e022f1950f31fe53a7c5).
- If you run 6.0, follow vendor guidance because no fixed commit is listed for that branch.
- Limit unprivileged users' ability to create or send crafted UDPv6 messages where possible, and monitor hosts for suspicious local network activity.
- Apply vendor-provided patches or backported fixes and monitor systems for indicators of compromise if immediate updates are not possible.
Frequently asked questions
Is CVE-2026-53362 being actively exploited?
CISA added CVE-2026-53362 to the Known Exploited Vulnerabilities catalog on 2026-08-27, and US federal agencies must remediate by 2026-08-30.
Which Linux Kernel versions are affected by CVE-2026-53362?
Affected branches listed include 14200.x, 65.x, 46.x, 6374.x, mainline Linux, 736.x, and 6.x (6.0 is listed with no fixed commit provided).
Is there a patch for CVE-2026-53362?
Yes — fixed commits are available for multiple branches (for example commits 14200d435af9a9eeb444f529fc2f689a236b7962, 65fb14cbebb0cd0eff903a22d33537ddc8b95769, 46f201f8b4c39633a1fa3dc12459f506d470993d, 6374fb9edf72c67a118a2c214a0dddd04c921e0a, e9eacf19281ea2498b36291b56c9606118c2d74e, 736b380e28d0480c7bc3e022f1950f31fe53a7c5); follow your vendor instructions to obtain the appropriate update.
Does CVE-2026-53362 require authentication?
No authentication is required beyond unprivileged local access: an unprivileged user can trigger the issue via a UDPv6 socket using MSG_MORE with MSG_SPLICE_PAGES.
References
- nvd.nist.gov/vuln/detail/CVE-2026-53362
- cve.org/CVERecord?id=CVE-2026-53362
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53362
- git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962
- git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769
- git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d
- git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a
- git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e
- git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5
- All Linux CVEs on CVE Radar
- CVEs published in September 2026