CVE-2026-53074 Details
Description
In the Linux kernel, the following vulnerability has been resolved: bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb bpf_prog_test_run_skb() calls eth_type_trans() first and then uses skb->protocol to initialize sk family and address fields for the test run. For IPv4 and IPv6 packets, it may access ip_hdr(skb) or ipv6_hdr(skb) even when the provided test input only contains an Ethernet header. Reject the input earlier if the Ethernet frame carries IPv4/IPv6 EtherType but the L3 header is too short. Fold the IPv4/IPv6 header length checks into the existing protocol switch and return -EINVAL before accessing the network headers.
A vulnerability in the Linux kernel's handling of short IPv4 and IPv6 inputs in the BPF (Berkeley Packet Filter) program test run function has been addressed. The issue arose because the function would access the IP headers based on the Ethernet frame's protocol, even when the Layer 3 header was too short. This could lead to incorrect socket family and address initialization. The vulnerability affects several versions of the Linux kernel.
The vulnerability has been fixed in the Linux kernel stable tree. Users can upgrade to the latest version to address this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0a04db240effd85773f66244645a28cedddb72d2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/12bec2bd4b76d81c5d3996bd14ec1b7f4d983747 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1f882c492d46f90bdb36f4936876c88c28dab21c | kernel.org | Patch |
| https://git.kernel.org/stable/c/6a9f38d5ff11e00bc54baab752642978805e81eb | kernel.org | Patch |
| https://git.kernel.org/stable/c/6def5fe753cbe5b279ee5fd10327b2611cbddaca | kernel.org | Patch |
| https://git.kernel.org/stable/c/7254267799d083280c0e53effc101a33add95f7b | kernel.org | Patch |
| https://git.kernel.org/stable/c/8042240412de3222d27b31e89d29336961cad9e4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e6aa481f21fc7a41ed344767ea25aae9d03fae71 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.9, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.141 >= 6.7, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | New CVE Received | kernel.org |