CVE-2026-5336 is a local privilege escalation vulnerability in the Linux kernel's IPv4 UDP implementation. The flaw affects UDP packet handling under specific MTU-dependent fragmentation conditions involving UDP_CORK and MSG_SPLICE_PAGES. Incorrect buffer management can cause packet metadata to be written past the end of the intended allocation, corrupting skb_shared_info, including its nr_frags field. This corruption can subsequently trigger a use-after-free condition in kernel memory. The issue was introduced in Linux kernel 6.1 and is associated with fragmented UDP processing paths in the IPv4 stack.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel privilege escalation vulnerability in IPv4 UDP fragmentation/packet handling related to Frag Gap, causing memory corruption and use-after-free that may allow local root escalation.
A Linux kernel IPv4 UDP fragmentation/use-after-free vulnerability that can enable local privilege escalation to root under specific packet handling conditions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.