Answer in brief
CVE-2026-53223 records a High severity (CVSS 7.1) vulnerability in net: guard timestamp cmsgs to real error queue skbs. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-53223 records a High severity (CVSS 7.1) vulnerability in net: guard timestamp cmsgs to real error queue skbs. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8605330aac5a5785630aec8f64378a54891937cc <24a0d548d3a765cd4558224e4f8e06e14cba26e3 || >=8605330aac5a5785630aec8f64378a54891937cc <71ff5cdd5da61d0438e902aa0fd68c28bc901abe || >=8605330aac5a5785630aec8f64378a54891937cc <ad9a0374ee6d11048e1f74cd5180bad58b9848b4 || >=8605330aac5a5785630aec8f64378a54891937cc <b903e9b5629ec8dd6db92174070045bf81ad7060 || >=8605330aac5a5785630aec8f64378a54891937cc <e0665b2a8e90bb08bd205062c75662b502d31797 || >=8605330aac5a5785630aec8f64378a54891937cc <3dde4fb941fa5649ab809f6cd3e20e0c424a4e31 || >=8605330aac5a5785630aec8f64378a54891937cc <eb51a9ad3ceb01bc6c0fb608dbc856e03ee6f24a || >=8605330aac5a5785630aec8f64378a54891937cc <1ee90b77b727df903033db873c75caac5c27ec98 || cdaf15b43bd31003220cb080bcbbd57787a2fca9 || >=4.10.14 <4.11 | 24a0d548d3a765cd4558224e4f8e06e14cba26e3, 71ff5cdd5da61d0438e902aa0fd68c28bc901abe, ad9a0374ee6d11048e1f74cd5180bad58b9848b4, b903e9b5629ec8dd6db92174070045bf81ad7060, e0665b2a8e90bb08bd205062c75662b502d31797, 3dde4fb941fa5649ab809f6cd3e20e0c424a4e31, eb51a9ad3ceb01bc6c0fb608dbc856e03ee6f24a, 1ee90b77b727df903033db873c75caac5c27ec98, 4.11 |
| Linux/Linuxgeneric | 4.11 | Not reported |
Published upstream
Jun 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue skbs skb_is_err_queue() treats PACKET_OUTGOING as the sole marker for an skb from sk_error_queue. That assumption is not true for AF_PACKET sockets: outgoing packet taps are also delivered to packet sockets with skb->pkt_type == PACKET_OUTGOING, but their skb->cb is owned by AF_PACKET instead of struct sock_exterr_skb. If such an skb is received with timestamping enabled, the generic timestamp cmsg path can read AF_PACKET control-buffer state as sock_exterr_skb::opt_stats. With SO_RXQ_OVFL enabled, the packet drop counter overlaps opt_stats. An odd drop count makes the path emit SCM_TIMESTAMPING_OPT_STATS with skb->len and skb->data. For non-linear skbs this copies past the linear head and can trigger hardened usercopy or disclose adjacent heap contents. Keep skb_is_err_queue() local to net/socket.c, but make it verify that the PACKET_OUTGOING marker is paired with the sock_rmem_free destructor installed by sock_queue_err_skb(). AF_PACKET receive skbs use normal receive ownership and no longer pass as error-queue skbs, while legitimate sk_error_queue entries keep the PACKET_OUTGOING marker and sock_rmem_free ownership.
Quoted source text, attributed separately from HOL analysis.
CVSS is 7.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8605330aac5a5785630aec8f64378a54891937cc <24a0d548d3a765cd4558224e4f8e06e14cba26e3 || >=8605330aac5a5785630aec8f64378a54891937cc <71ff5cdd5da61d0438e902aa0fd68c28bc901abe || >=8605330aac5a5785630aec8f64378a54891937cc <ad9a0374ee6d11048e1f74cd5180bad58b9848b4 || >=8605330aac5a5785630aec8f64378a54891937cc <b903e9b5629ec8dd6db92174070045bf81ad7060 || >=8605330aac5a5785630aec8f64378a54891937cc <e0665b2a8e90bb08bd205062c75662b502d31797 || >=8605330aac5a5785630aec8f64378a54891937cc <3dde4fb941fa5649ab809f6cd3e20e0c424a4e31 || >=8605330aac5a5785630aec8f64378a54891937cc <eb51a9ad3ceb01bc6c0fb608dbc856e03ee6f24a || >=8605330aac5a5785630aec8f64378a54891937cc <1ee90b77b727df903033db873c75caac5c27ec98 || cdaf15b43bd31003220cb080bcbbd57787a2fca9 || >=4.10.14 <4.11 | 24a0d548d3a765cd4558224e4f8e06e14cba26e3, 71ff5cdd5da61d0438e902aa0fd68c28bc901abe, ad9a0374ee6d11048e1f74cd5180bad58b9848b4, b903e9b5629ec8dd6db92174070045bf81ad7060, e0665b2a8e90bb08bd205062c75662b502d31797, 3dde4fb941fa5649ab809f6cd3e20e0c424a4e31, eb51a9ad3ceb01bc6c0fb608dbc856e03ee6f24a, 1ee90b77b727df903033db873c75caac5c27ec98, 4.11 |
| Linux/Linuxgeneric | 4.11 | Not reported |
Published upstream
Jun 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue skbs skb_is_err_queue() treats PACKET_OUTGOING as the sole marker for an skb from sk_error_queue. That assumption is not true for AF_PACKET sockets: outgoing packet taps are also delivered to packet sockets with skb->pkt_type == PACKET_OUTGOING, but their skb->cb is owned by AF_PACKET instead of struct sock_exterr_skb. If such an skb is received with timestamping enabled, the generic timestamp cmsg path can read AF_PACKET control-buffer state as sock_exterr_skb::opt_stats. With SO_RXQ_OVFL enabled, the packet drop counter overlaps opt_stats. An odd drop count makes the path emit SCM_TIMESTAMPING_OPT_STATS with skb->len and skb->data. For non-linear skbs this copies past the linear head and can trigger hardened usercopy or disclose adjacent heap contents. Keep skb_is_err_queue() local to net/socket.c, but make it verify that the PACKET_OUTGOING marker is paired with the sock_rmem_free destructor installed by sock_queue_err_skb(). AF_PACKET receive skbs use normal receive ownership and no longer pass as error-queue skbs, while legitimate sk_error_queue entries keep the PACKET_OUTGOING marker and sock_rmem_free ownership.
Quoted source text, attributed separately from HOL analysis.