Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-53363

xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()
Back to all
CVE

CVE-2026-53363

xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()

In the Linux kernel, the following vulnerability has been resolved:

xfrm: iptfs: preserve shared-frag marker in iptfsconsumefrags()

iptfsconsumefrags() transfers paged fragments from one socket buffer

to another but fails to propagate the SKBFLSHAREDFRAG flag. This is

the same class of bug that was fixed in skbtrycoalesce() for

CVE-2026-46300: when fragments backed by read-only page-cache pages are

merged, the marker indicating their shared nature must be preserved so

that ESP can decide correctly whether in-place encryption is safe.

Apply the same two-line fix used in skbtrycoalesce() to

iptfsconsumefrags().

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/c885d111ed9f5a0a1f3cc4e87a50db6518abaa6c, https://git.kernel.org/stable/c/dd66f7f6e360ee82cd905517726f8e9091265de5, https://git.kernel.org/stable/c/e9096a5a170e7ecd6467bc2e08668ec39897cda7, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53363.json, https://nvd.nist.gov/vuln/detail/CVE-2026-53363, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00411%
EPSS Percentile
0.34285%
Introduced Version
b96ba312e21c9b7ac1526829b9640ddc06695c0b,6.14.0,6.19.0,0
Fix Available
e9096a5a170e7ecd6467bc2e08668ec39897cda7,6.18.36,7.0.13

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading