CVE-2026-53014 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_blockcast_redir In tcf_blockcast_redir(), when iterating block ports to redirect packets to multiple devices, the mac_header_xmit flag is queried from the wrong device. The loop sends to dev_prev but queries dev_is_mac_header_xmit(dev) — which is the NEXT device in the iteration, not the one being sent to. This causes tcf_mirred_to_dev() to make incorrect decisions about whether to push or pull the MAC header. When the block contains mixed device types (e.g., an ethernet veth and a tunnel device), intermediate devices get the wrong mac_header_xmit flag, leading to skb header corruption. In the worst case, skb_push_rcsum with an incorrect mac_len can exhaust headroom and panic. The last device in the loop is handled correctly (line 365-366 uses dev_is_mac_header_xmit(dev_prev)), confirming this is a copy-paste oversight for the intermediate devices. Fix by using dev_prev instead of dev for the mac_header_xmit query, consistent with the device actually being sent to.
A vulnerability exists in the Linux kernel's networking scheduler, specifically within the 'act_mirred' module. The issue arises in the 'tcf_blockcast_redir' function, where the 'mac_header_xmit' flag is incorrectly retrieved from the device being sent to. This misalignment can lead to improper handling of packet headers, especially when different types of network devices are involved, such as Ethernet and tunnel interfaces. The error can cause corruption of the socket buffer headers, and in severe cases, deplete the available headroom, leading to a system panic.
Users can apply the available patch to address this vulnerability. The patch is included in the official Linux kernel repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/4510d140524ca7d6e772db962e013f26f09a63b1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4764953c4b47585eb72797b216b63a831dc0c7e6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7db3e4e03032261b1b519341123fc30d995478ca | kernel.org | Patch |
| https://git.kernel.org/stable/c/8fda5174286119addd28473fb2ec5bdf521c05a8 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.8, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | New CVE Received | kernel.org |