CVE-2026-53006: ipv6: fix possible UAF in icmpv6_rcv()
Published Jun 24, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
14 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.139.1-1<6.6.143.1-1
6.6.143.1-1
Linux Linux kernel>=4.4<5.10.258
Linux Linux kernel>=5.11<5.15.209
Linux Linux kernel>=5.16<6.1.175
Linux Linux kernel>=6.2<6.6.141
Linux Linux kernel>=6.7<6.12.91
Linux Linux kernel>=6.13<6.18.33
Linux Linux kernel>=6.19<7.0.10
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0
debian/linux<=5.10.223-1
5.10.262-16.1.176-16.1.180-16.12.94-16.12.101-17.1.8-17.1.8-2
debian/linux-6.1
6.1.180-1~deb11u1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.143.1-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.180-1~deb11u1
Event History
Jun 24, 2026
CVE Published
via MITRE·04:29 PM
Data Sourced
via MITRE·04:29 PM
DescriptionSeverity
Data Sourced
via NVD·05:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·06:07 PM
DescriptionSeverityAffected Software
Jun 27, 2026
Data Sourced
via Microsoft·08:14 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:14 AM
Affected Software
Updated
via Microsoft·08:14 AM
DescriptionSeverity
Aug 13, 2026
Data Sourced
via Launchpad·08:41 PM
Description
Aug 16, 2026
Data Sourced
via Debian·08:44 PM
DescriptionAffected Software
Aug 17, 2026
Data Sourced
via Ubuntu·08:44 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-53006?
CVE-2026-53006 has a critical severity score of 9.8.
2
What does CVE-2026-53006 affect?
CVE-2026-53006 affects the Linux kernel specifically related to IPv6 processing.
3
How do I fix CVE-2026-53006?
To fix CVE-2026-53006, update your Linux kernel to the latest version that addresses this vulnerability.
4
What type of vulnerability is CVE-2026-53006?
CVE-2026-53006 is a use-after-free (UAF) vulnerability in the ICMPv6 receive function.
5
When was CVE-2026-53006 published?
CVE-2026-53006 was published on June 24, 2026.