Two Linux kernel vulnerabilities, CVE-2026-53362 and CVE-2026-53366, were disclosed in the UDP packet handling path and can allow a local unprivileged user to escalate privileges to root. The flaws affect the IPv6 UDPv6 path and the IPv4 UDP path when MSG_SPLICE_PAGES is used with UDP corking and a datagram crosses a fragment boundary, causing a heap out-of-bounds write. Researchers said incorrect fraggap accounting lets validation be bypassed, leading to corruption of skb_shared_info metadata and manipulation of the nr_frags field, which can ultimately produce a use-after-free condition exploitable for local privilege escalation.
The bugs affect Linux kernels from v6.1 onward. The IPv6 issue requires CONFIG_IPV6=y, while the IPv4 variant also depends on access conditions tied to user namespaces. Fixes were published in upstream commits 736b380e28d0 for IPv6 and eca856950f7c for IPv4, and were released in stable kernel versions including 7.1.3, 6.18.38, 6.12.95, 6.6.144, and 6.1.177. Advisories or updates were issued by major distributions including Debian, Ubuntu, SUSE/openSUSE, RHEL, Gentoo, Arch, and Fedora.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Canonical published an Ubuntu security tracker page for CVE-2026-53362, documenting Ubuntu's handling of the Linux kernel Frag Gap vulnerability. This adds an official Ubuntu vendor reference for the flaw separate from previously noted upstream and Red Hat disclosures.
Red Hat stated that CVE-2026-53362 was addressed via RHSA advisories for Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, and NVIDIA for RHEL 10. The Bugzilla entry also summarized the IPv6 __ip6_append_data() memory-corruption flaw and its fix.
An oss-sec disclosure detailed the root cause of the Linux kernel UDP out-of-bounds write issues, explaining incorrect fraggap accounting in IPv6 and IPv4 append-data paths and the resulting controlled overwrite of skb_shared_info. The post assessed the bugs as exploitable for local privilege escalation by an unprivileged local user under the stated conditions.
The vulnerable UDP fragment-boundary handling that led to CVE-2026-53362 and CVE-2026-53366 was introduced starting with Linux kernel v6.1. The flaws affect IPv6 and IPv4 UDP paths when MSG_SPLICE_PAGES is used in corked datagrams crossing a fragment boundary.
OpenNet disclosed two newly assigned CVEs, CVE-2026-53362 and CVE-2026-53366, describing local privilege-escalation flaws in Linux UDP handling dubbed Frag Gap. The report said major Linux distributions, including Debian, Ubuntu, SUSE/openSUSE, RHEL, Gentoo, Arch, and Fedora, had issued or were preparing advisories and updates.
Fixes for the IPv6 and IPv4 Frag Gap vulnerabilities were published on June 21, including commits 736b380e28d0 for IPv6 and eca856950f7c for IPv4. OpenNet reports the fixes were released in stable kernel versions 7.1.3, 6.18.38, 6.12.95, 6.6.144, and 6.1.177.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcesecurity-tracker.debian.org
Open sourceblog.qwerty.or.kr
Open sourcepeople.canonical.com
Open sourcegit.kernel.org
Open sourceseclists.org
Open sourceopennet.ru
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.