CVE-2026-53175: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.1.13-1 - Upgrade
Upgrade
Linux kernel inet: fragsto a version that resolves this vulnerability.Fixed in 10 September 2026 - Configuration
Ensure inet_frag_queue_flush() resets rb_fragments, fragments_tail, and last_run_head so that a flushed queue no longer points at freed skbs (fixes UAF after fqdir_pre_exit() flush on netns teardown).
Linux kernel inet frag reassembly / fqdir_pre_exit() Reset rb_fragments, fragments_tail and last_run_head in inet_frag_queue_flush() = applied - Configuration
Drop the now-duplicate reset code in inet_frag_queue_flush() since ip_frag_reinit() already performs the required reset after its own flush.
Linux kernel ip frag reinit() Duplicate reset logic in inet_frag_queue_flush() = remove duplicate
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53175?
CVE-2026-53175 has a risk score of 47, indicating a moderate level of severity.
How do I fix CVE-2026-53175?
Fixing CVE-2026-53175 involves updating the Linux kernel to the latest patched version that addresses this use-after-free vulnerability.
What types of systems are affected by CVE-2026-53175?
CVE-2026-53175 affects systems running certain versions of the Linux kernel that are utilizing the inet fragment handling mechanism.
Can CVE-2026-53175 be exploited remotely?
Yes, CVE-2026-53175 can potentially be exploited remotely if an attacker can manipulate network traffic to trigger the vulnerability.
What is the primary cause of CVE-2026-53175?
The primary cause of CVE-2026-53175 is a use-after-free error related to the fqdir_pre_exit() function during network namespace teardown.