CVE-2026-53091
Medium
Elevated severity or exploit probability.
CVSS base
8.4
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
EPSS — probability of exploitation (30 days)
0.1%
3.3th percentile
CISA KEV
Not listed
Weakness / dates
CWE-131
Published 2026-06-24 · modified 2026-09-14
CVSS breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
| Attack Vector | L | Local |
| Attack Complexity | L | Low |
| Privileges Required | L | Low |
| User Interaction | N | None |
| Scope | C | Changed |
| Confidentiality | H | High |
| Integrity | N | None |
| Availability | H | High |
Timeline
- 2026-06-24 — Published (NVD)
- 2026-09-14 — Last modified (NVD)
Description
In the Linux kernel, the following vulnerability has been resolved: net: pull headers in qdisc_pkt_len_segs_init() Most ndo_start_xmit() methods expects headers of gso packets to be already in skb->head. net/core/tso.c users are particularly at risk, because tso_build_hdr() does a memcpy(hdr, skb->data, hdr_len); qdisc_pkt_len_segs_init() already does a dissection of gso packets. Use pskb_may_pull() instead of skb_header_pointer() to make sure drivers do not have to reimplement this. Some malicious packets could be fed, detect them so that we can drop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.
Affected
References
- https://git.kernel.org/stable/c/7fb4c19670110f052c04e1ec1d2b953b9f4f57e4
- https://git.kernel.org/stable/c/9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a
- https://access.redhat.com/errata/RHSA-2026:65334
- https://access.redhat.com/errata/RHSA-2026:66324
- https://access.redhat.com/errata/RHSA-2026:66325
- https://access.redhat.com/errata/RHSA-2026:67150
- https://access.redhat.com/security/cve/CVE-2026-53091
- https://bugzilla.redhat.com/show_bug.cgi?id=2492270
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53091.json