CVE-2026-53221: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
Published Jun 25, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Other sources
ip6vti: fix incorrect tunnel matching in vti6tnllookup()
— Microsoft
Affected Software
17 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.141.1-1<6.6.143.1-1
6.6.143.1-1
Linux Linux kernel>=3.19<5.10.259
Linux Linux kernel>=5.11<5.15.210
Linux Linux kernel>=5.16<6.1.176
Linux Linux kernel>=6.2<6.6.143
Linux Linux kernel>=6.7<6.12.94
Linux Linux kernel>=6.13<6.18.36
Linux Linux kernel>=6.19<7.0.13
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3
Linux Linux kernel=7.1-rc4
Linux Linux kernel=7.1-rc5
Linux Linux kernel=7.1-rc6
Linux Linux kernel=7.1-rc7
debian/linux
6.1.176-16.1.187-16.12.107-16.12.111-17.2.6-17.2.8-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.143.1-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 6.12.111-1Fixed in 7.2.6-1Fixed in 7.2.8-1
Event History
Jun 25, 2026
CVE Published
via MITRE·08:39 AM
Data Sourced
via MITRE·08:39 AM
DescriptionSeverity
Data Sourced
via NVD·09:16 AM
RemedyDescriptionSeverityAffected Software
Jun 27, 2026
Data Sourced
via Microsoft·08:18 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:18 AM
DescriptionSeverity
Aug 13, 2026
Data Sourced
via Launchpad·08:41 PM
Description
Sep 29, 2026
Data Sourced
via Debian·11:28 AM
DescriptionAffected Software
Sep 30, 2026
Data Sourced
via Ubuntu·11:27 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-53221?
CVE-2026-53221 has a critical severity rating of 9.8.
2
What does CVE-2026-53221 affect?
CVE-2026-53221 affects the Linux kernel, specifically related to incorrect tunnel matching in the vti6_tnl_lookup() function.
3
How do I fix CVE-2026-53221?
To fix CVE-2026-53221, apply the available patch released by the Linux kernel.
4
What are the potential impacts of CVE-2026-53221?
CVE-2026-53221 could lead to unauthorized access to network traffic due to incorrect tunnel matching.
5
When was CVE-2026-53221 published?
CVE-2026-53221 was published on June 25, 2026.