Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags() iptfs_consume_frags() transfers paged fragments from one socket buffer to another but fails to propagate the SKBFL_SHARED_FRAG flag. This is the same class of bug that was fixed in skb_try_coalesce() for CVE-2026-46300: when fragments backed by read-only page-cache pages are merged, the marker indicating their shared nature must be preserved so that ESP can decide correctly whether in-place encryption is safe. Apply the same two-line fix used in skb_try_coalesce() to iptfs_consume_frags().
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.14, < 6.18.36 |
References
- https://git.kernel.org/stable/c/c885d111ed9f5a0a1f3cc4e87a50db6518abaa6cPatch
- https://git.kernel.org/stable/c/dd66f7f6e360ee82cd905517726f8e9091265de5Patch
- https://git.kernel.org/stable/c/e9096a5a170e7ecd6467bc2e08668ec39897cda7Patch
FAQ
What is CVE-2026-53363?
CVE-2026-53363 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags() iptfs_consume_frags() transfers paged fragments from one socket ...
How severe is CVE-2026-53363?
CVE-2026-53363 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-53363?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.