cbcvebase.
CVE-2026-53091
published 2026-06-24

CVE-2026-53091: In the Linux kernel, the following vulnerability has been resolved: net: pull headers in qdisc_pkt_len_segs_init() Most ndo_start_xmit() methods expects…

PriorityP340high8.4CVSS 3.1
AVLACLPRLUINSCCHINAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net: pull headers in qdisc_pkt_len_segs_init() Most ndo_start_xmit() methods expects headers of gso packets to be already in skb->head. net/core/tso.c users are particularly at risk, because tso_build_hdr() does a memcpy(hdr, skb->data, hdr_len); qdisc_pkt_len_segs_init() already does a dissection of gso packets. Use pskb_may_pull() instead of skb_header_pointer() to make sure drivers do not have to reimplement this. Some malicious packets could be fed, detect them so that we can drop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.

Affected

13 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= e876f208af18b074f800656e4d1b99da75b2135f < 9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a
linuxlinux>= e876f208af18b074f800656e4d1b99da75b2135f < 7fb4c19670110f052c04e1ec1d2b953b9f4f57e47fb4c19670110f052c04e1ec1d2b953b9f4f57e4
linuxlinux_kernel
linuxlinux_kernel>= 3.16 < 7.0.107.0.10
ubuntulinux
ubuntulinux-gcp
ubuntulinux-gke
ubuntulinux-hwe-7.0
ubuntulinux-ibm
ubuntulinux-oem-7.0
ubuntulinux-oracle
ubuntulinux-realtime

CVSS provenance

nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
vendor_redhat7.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.