Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

CVE-2026-53250: Linux Kernel Vulnerability: Malicious Userspace Overwrites

CVE-2026-53250
Summary

A Linux kernel vulnerability allows a malicious application to bypass checks and access memory outside its allowed range, potentially causing data corruption or system crashes. This issue affects Linux systems and can be mitigated by updating the kernel to the fixed version. It is recommended to apply the kernel update as soon as possible to ensure system security and stability.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
linux linux_kernel >= 6.8, < 6.18.36
>= 6.19, < 7.0.13
7.1
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Original title
In the Linux kernel, the following vulnerability has been resolved: xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() The TX metadata area resides in the UMEM buffer which is ...
Original description
In the Linux kernel, the following vulnerability has been resolved:

xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()

The TX metadata area resides in the UMEM buffer which is memory-mapped
and concurrently writable by userspace. In xsk_skb_metadata(),
csum_start and csum_offset are read from shared memory for bounds
validation, then read again for skb assignment. A malicious userspace
application can race to overwrite these values between the two reads,
bypassing the bounds check and causing out-of-bounds memory access
during checksum computation in the transmit path.

Fix this by reading csum_start and csum_offset into local variables
once, then using the local copies for both validation and assignment.

Note that other metadata fields (flags, launch_time) and the cached
csum fields may be mutually inconsistent due to concurrent userspace
writes, but this is benign: the only security-critical invariant is
that each field's validated value is the same one used, which local
caching guarantees.
Vulnerability type
CWE-367
Published: 25 Jun 2026 · Updated: 9 Jul 2026 · First seen: 25 Jun 2026