Bug 2501252 (CVE-2026-53366) - CVE-2026-53366 kernel: ipv4: account for fraggap on the paged allocation path
Summary: CVE-2026-53366 kernel: ipv4: account for fraggap on the paged allocation path
Keywords:
Status: NEW
Alias: CVE-2026-53366
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-16 06:01 UTC by OSIDB Bzimport
Modified: 2026-09-09 22:05 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:66180 0 None None None 2026-09-09 22:05:01 UTC

Description OSIDB Bzimport 2026-07-16 06:01:51 UTC
In the Linux kernel, the following vulnerability has been resolved:

ipv4: account for fraggap on the paged allocation path

In __ip_append_data(), when the paged-allocation branch is taken,
alloclen and pagedlen are computed as

	alloclen = fragheaderlen + transhdrlen;
	pagedlen = datalen - transhdrlen;

datalen already includes fraggap, but the fraggap bytes carried over
from the previous skb are copied into the new skb's linear area at
offset transhdrlen by the subsequent skb_copy_and_csum_bits(). The
linear area is therefore undersized by fraggap bytes while pagedlen is
overstated by the same amount.

The non-paged branch sets alloclen to fraglen, which already accounts
for fraggap because datalen does. Bring the paged branch in line by
adding fraggap to alloclen and subtracting it from pagedlen.

After this adjustment, copy no longer collapses to -fraggap on the
paged path, so remove the stale comment describing that old arithmetic.

Comment 1 Mauro Matteo Cascella 2026-07-17 09:34:29 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026071639-CVE-2026-53366-f508@gregkh/T

Comment 7 Akiyoshi Kurita 2026-07-22 19:39:57 UTC
A public exploit write-up related to CVE-2026-53366 has been disclosed:

https://blog.qwerty.or.kr/en/posts/cdf3008a-c1a4-4eca-a373-aa3a2bcf1489/

The researchers state that the corresponding IPv4 issue is also exploitable. 
Could you please review whether this changes the current exploitability assessment?

Comment 9 errata-xmlrpc 2026-09-09 22:05:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:66180 https://access.redhat.com/errata/RHSA-2026:66180


Note You need to log in before you can comment on or make changes to this bug.