CVE-2026-53006
A critical flaw in the Linux kernel’s IPv6 handling can let an attacker crash the system or run arbitrary code. The bug is a use‑after‑free in the icmpv6_rcv() function when processing IPv6 packets. It has been fixed in newer kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, including Red Hat Enterprise Linux 8.0, 9.0, and 10.0.
Real-world impact
An attacker could cause a denial‑of‑service crash or potentially execute code with kernel privileges, leading to full system compromise.
Why this severity
The CVSS score of 9.8 reflects the vulnerability’s high impact on confidentiality, integrity, and availability, and the fact that it can be exploited remotely without authentication or user interaction.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix.
- 02Reboot the system to load the updated kernel.
NVD-referenced vendor advisory
Timeline
- Jun 24, 2026 · Jun 24, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 7d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 28, 2026 · 7d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/0069813e6ca9309eca…patch
- git.kernel.org/stable/c/085e31a811ef234ef8…patch
- git.kernel.org/stable/c/1e1f0f89ee4692a64b…patch
- git.kernel.org/stable/c/38bdbc897c0d83a3e2…patch
- git.kernel.org/stable/c/7bff2c8fe5c35ae58b…patch
- git.kernel.org/stable/c/7c66b368c6ff453f99…patch
- git.kernel.org/stable/c/aff0f28f5be803de24…patch
- git.kernel.org/stable/c/f996edd7615e686ada…patch
- access.redhat.com/errata/RHSA-2026:45192
- access.redhat.com/errata/RHSA-2026:47010
- access.redhat.com/errata/RHSA-2026:47011
- access.redhat.com/errata/RHSA-2026:47017
- access.redhat.com/security/cve/CVE-2026-53006third party advisory
- bugzilla.redhat.com/show_bug.cgithird party advisory
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2…third party advisory