High severity8.4NVD Advisory· Published Jun 24, 2026· Updated Jul 23, 2026
CVE-2026-53091
CVE-2026-53091
Description
In the Linux kernel, the following vulnerability has been resolved:
net: pull headers in qdisc_pkt_len_segs_init()
Most ndo_start_xmit() methods expects headers of gso packets to be already in skb->head.
net/core/tso.c users are particularly at risk, because tso_build_hdr() does a memcpy(hdr, skb->data, hdr_len);
qdisc_pkt_len_segs_init() already does a dissection of gso packets.
Use pskb_may_pull() instead of skb_header_pointer() to make sure drivers do not have to reimplement this.
Some malicious packets could be fed, detect them so that we can drop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.
Affected products
4Patches
Vulnerability mechanics
References
5- git.kernel.org/stable/c/7fb4c19670110f052c04e1ec1d2b953b9f4f57e4nvdPatch
- git.kernel.org/stable/c/9d4f5c68f5ad4ab425f3ce1500c97c9f9743999anvdPatch
- access.redhat.com/security/cve/CVE-2026-53091nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdThird Party Advisory
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53091.jsonnvdThird Party Advisory
News mentions
1- Android SDK: 13 Kernel Networking CVEs Patched in June 2026 BulletinVypr Intelligence · Jun 25, 2026