CVE-2026-53228
published 2026-06-25CVE-2026-53228: In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offloads ipip6_tunnel_xmit() caches the inner…
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.56%
42.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
ipv6: sit: reload inner IPv6 header after GSO offloads
ipip6_tunnel_xmit() caches the inner IPv6 header pointer at function
entry and continues using it after iptunnel_handle_offloads().
For GSO skbs, iptunnel_handle_offloads() calls skb_header_unclone().
When the skb header is cloned, skb_header_unclone() can call
pskb_expand_head(), which may move the skb head. The pskb_expand_head()
contract requires pointers into the skb header to be reloaded after the
call.
If the later skb_realloc_headroom() branch is not taken, SIT uses the
stale iph6 pointer to read the inner hop limit and DS field. That can
read from a freed skb head after the old head's remaining clone is
released.
Reload iph6 after the offload helper succeeds and before subsequent
reads from the inner IPv6 header. Keep the existing reload after
skb_realloc_headroom(), since that branch can also replace the skb.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 14909664e4e192f4c6f6fcdccd9919af7cf783ab < fddd41445a0537b093e6b3f6232c9933cad1e48b | fddd41445a0537b093e6b3f6232c9933cad1e48b |
| linux | linux | >= 14909664e4e192f4c6f6fcdccd9919af7cf783ab < 1132e5edc2866c3530be17622153a597095f0e43 | 1132e5edc2866c3530be17622153a597095f0e43 |
| linux | linux | >= 14909664e4e192f4c6f6fcdccd9919af7cf783ab < 9c67b44edb3598d234efae6e44649eb993c03da5 | 9c67b44edb3598d234efae6e44649eb993c03da5 |
| linux | linux | >= 14909664e4e192f4c6f6fcdccd9919af7cf783ab < 0bfa7bba1f41aaf5f0604dc712bb4701493e3aa0 | 0bfa7bba1f41aaf5f0604dc712bb4701493e3aa0 |
| linux | linux | >= 14909664e4e192f4c6f6fcdccd9919af7cf783ab < 59f80c919713250fe5d25a4d9aea4e49580fa1d4 | 59f80c919713250fe5d25a4d9aea4e49580fa1d4 |
| linux | linux | >= 14909664e4e192f4c6f6fcdccd9919af7cf783ab < 2fa49b2715e1bad12ce3b0fa64e234d9582c8193 | 2fa49b2715e1bad12ce3b0fa64e234d9582c8193 |
| linux | linux | >= 14909664e4e192f4c6f6fcdccd9919af7cf783ab < cb658c2f5f7977c2a1c77c9f239f4bc8196edb5c | cb658c2f5f7977c2a1c77c9f239f4bc8196edb5c |
| linux | linux | >= 14909664e4e192f4c6f6fcdccd9919af7cf783ab < f0e42f0c4337b1f220de1ddd63f47197c7dee4de | f0e42f0c4337b1f220de1ddd63f47197c7dee4de |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 3.18 < 5.10.259 | 5.10.259 |
| linux | linux_kernel | >= 5.11 < 5.15.210 | 5.15.210 |
| linux | linux_kernel | >= 5.16 < 6.1.176 | 6.1.176 |
| linux | linux_kernel | >= 6.13 < 6.18.36 | 6.18.36 |
| linux | linux_kernel | >= 6.19 < 7.0.13 | 7.0.13 |
| linux | linux_kernel | >= 6.2 < 6.6.143 | 6.6.143 |
| linux | linux_kernel | >= 6.7 < 6.12.94 | 6.12.94 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offloads ipip6_tunnel_xmit() caches the inner IPv6 header pointer at function entry
ghsa_unreviewed·2026-06-25
CVE-2026-53228 In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offloads ipip6_tunnel_xmit() caches the inner IPv6 header pointer at function entry
In the Linux kernel, the following vulnerability has been resolved:
ipv6: sit: reload inner IPv6 header after GSO offloads
ipip6_tunnel_xmit() caches the inner IPv6 header pointer at function
entry and continues using it after iptunnel_handle_offloads().
For GSO skbs, iptunnel_handle_offloads() calls skb_header_unclone().
When the skb header is cloned, skb_header_unclone() can call
pskb_expand_head(), which may move the skb head. The pskb_expand_head()
contract requires pointers into the skb header to be reloaded after the
call.
If the later skb_realloc_headroom() branch is not taken, SIT uses the
stale iph6 pointer to read the inner hop limit and DS field. That can
read from a freed skb head after the old head's remaining clone is
released.
Reload iph6 after the offload helper succee
Red Hat
kernel: ipv6: sit: reload inner IPv6 header after GSO offloads
vendor_redhat·2026-06-25·CVSS 7.0
CVE-2026-53228 [MEDIUM] CWE-825 kernel: ipv6: sit: reload inner IPv6 header after GSO offloads
kernel: ipv6: sit: reload inner IPv6 header after GSO offloads
A flaw was found in the Linux kernel's Simple Internet Transition (SIT) tunnel driver for IPv6. When processing network traffic with Generic Segmentation Offload (GSO) enabled, the driver may use a stale pointer to the inner IPv6 header after the socket buffer (skb) head has been reallocated. This can lead to reading from freed memory, potentially allowing an attacker to cause a denial of service or gain access to sensitive information.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Affected
Package: kernel (Red Hat Enterprise Linux 8) - Aff
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0bfa7bba1f41aaf5f0604dc712bb4701493e3aa0https://git.kernel.org/stable/c/1132e5edc2866c3530be17622153a597095f0e43https://git.kernel.org/stable/c/2fa49b2715e1bad12ce3b0fa64e234d9582c8193https://git.kernel.org/stable/c/59f80c919713250fe5d25a4d9aea4e49580fa1d4https://git.kernel.org/stable/c/9c67b44edb3598d234efae6e44649eb993c03da5https://git.kernel.org/stable/c/cb658c2f5f7977c2a1c77c9f239f4bc8196edb5chttps://git.kernel.org/stable/c/f0e42f0c4337b1f220de1ddd63f47197c7dee4dehttps://git.kernel.org/stable/c/fddd41445a0537b093e6b3f6232c9933cad1e48b
2026-06-25
Published