Out-of-bounds read in Linux kernel - CVE-2026-53151

 

Out-of-bounds read in Linux kernel - CVE-2026-53151

Published: June 26, 2026


Vulnerability identifier: #VU135635
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53151
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in rxrpc_input_soft_acks() when parsing the SACK table from a fragmented UDP packet. A remote attacker can send a deliberately fragmented packet to cause a denial of service.

The issue affects AF_RXRPC extended ACK parsing, and exploitation likely requires a deliberately pre-generated fragmented packet.


Affected software

Linux kernel
Debian Linux
Ubuntu
linux (Ubuntu package)
linux-lowlatency (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux (Debian package)
linux-hwe-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-aws-7.0 (Ubuntu package)

How to mitigate CVE-2026-53151

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 6.8.0-137.137+fips1, 6.8.0-1034.35, 6.8.0-1047.51, 6.8.0-1060.63.1, 6.8.0-1060.63~22.04.1, 6.8.0-1060.68, 6.8.0-1062.63, 6.8.0-1062.63~22.04.1, 6.8.0-1062.65, 6.8.0-1062.65+fips1, 6.8.0-1063.70, 6.8.0-1063.70~22.04.1, 6.8.0-1064.72+fips1, 6.8.0-1064.72~22.04.1, 6.8.0-1065.73, 6.8.0-1065.73+fips1, 6.8.0-1065.73~22.04.1, 6.8.1-1057.58, 6.8.1-1057.58~22.04.1, 7.0.0-29.29, 7.0.0-29.29.1, 7.0.0-1009.9, 7.0.0-1010.10, 7.0.0-1011.11, 7.0.0-1016.16
linux-lowlatency (Ubuntu package) - addressed in versions 6.8.0-137.137.1, 6.8.0-137.137.1~22.04.1, 6.8.0-1031.32, 6.8.0-1059.62
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1059.62~22.04.1
linux (Debian package) - update to 6.12.95-1
linux-hwe-7.0 (Ubuntu package) - update to 7.0.0-29.29~24.04.2
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1010.10
linux-aws-7.0 (Ubuntu package) - update to 7.0.0-1010.10~24.04.1

External References

Related Security Bulletins