CVE-2026-53221: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
In the Linux kernel, the following vulnerability has been resolved:
Other sources
ip6vti: fix incorrect tunnel matching in vti6tnllookup()
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.143.1-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-2Fixed in 7.1.9-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.180-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53221?
CVE-2026-53221 has a critical severity rating of 9.8.
What does CVE-2026-53221 affect?
CVE-2026-53221 affects the Linux kernel, specifically related to incorrect tunnel matching in the vti6_tnl_lookup() function.
How do I fix CVE-2026-53221?
To fix CVE-2026-53221, apply the available patch released by the Linux kernel.
What are the potential impacts of CVE-2026-53221?
CVE-2026-53221 could lead to unauthorized access to network traffic due to incorrect tunnel matching.
When was CVE-2026-53221 published?
CVE-2026-53221 was published on June 25, 2026.