Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-53363: Linux Kernel: Fragment Merging Vulnerability Resolved

CVE-2026-53363 CVE-2026-53363
Summary

A vulnerability in the Linux kernel's fragment merging feature has been fixed. This issue could allow hackers to manipulate encrypted data, potentially leading to unauthorized access. Affected systems should be updated to the latest kernel version to ensure security.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
linux linux < dd66f7f6e360ee82cd905517726f8e9091265de5
6.14
Original title
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags() iptfs_consume_frags() transfers paged fragments from one sock...
Original description
In the Linux kernel, the following vulnerability has been resolved:

xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()

iptfs_consume_frags() transfers paged fragments from one socket buffer
to another but fails to propagate the SKBFL_SHARED_FRAG flag. This is
the same class of bug that was fixed in skb_try_coalesce() for
CVE-2026-46300: when fragments backed by read-only page-cache pages are
merged, the marker indicating their shared nature must be preserved so
that ESP can decide correctly whether in-place encryption is safe.

Apply the same two-line fix used in skb_try_coalesce() to
iptfs_consume_frags().
Published: 10 Jul 2026 · Updated: 20 Jul 2026 · First seen: 10 Jul 2026