Bug 2501252 (CVE-2026-53366) - CVE-2026-53366 kernel: ipv4: account for fraggap on the paged allocation path
Summary: CVE-2026-53366 kernel: ipv4: account for fraggap on the paged allocation path
Keywords:
Status: NEW
Alias: CVE-2026-53366
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-16 06:01 UTC by OSIDB Bzimport
Modified: 2026-07-17 09:38 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-16 06:01:51 UTC
In the Linux kernel, the following vulnerability has been resolved:

ipv4: account for fraggap on the paged allocation path

In __ip_append_data(), when the paged-allocation branch is taken,
alloclen and pagedlen are computed as

	alloclen = fragheaderlen + transhdrlen;
	pagedlen = datalen - transhdrlen;

datalen already includes fraggap, but the fraggap bytes carried over
from the previous skb are copied into the new skb's linear area at
offset transhdrlen by the subsequent skb_copy_and_csum_bits(). The
linear area is therefore undersized by fraggap bytes while pagedlen is
overstated by the same amount.

The non-paged branch sets alloclen to fraglen, which already accounts
for fraggap because datalen does. Bring the paged branch in line by
adding fraggap to alloclen and subtracting it from pagedlen.

After this adjustment, copy no longer collapses to -fraggap on the
paged path, so remove the stale comment describing that old arithmetic.

Comment 1 Mauro Matteo Cascella 2026-07-17 09:34:29 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026071639-CVE-2026-53366-f508@gregkh/T


Note You need to log in before you can comment on or make changes to this bug.