IM
IronMonkey Threat Research

CVE-2026-53236 MEDIUM

Published: 2026-06-25 | Last Modified: 2026-09-08 | Status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: tcp: restrict SO_ATTACH_FILTER to priv users This patch restricts the use of SO_ATTACH_FILTER (cBPF) on TCP sockets to users with CAP_NET_ADMIN capability. This blocks potential side-channel attack where an unprivileged application attaches a filter to leak TCP sequence/acknowledgment numbers.

CVSS Metrics

Base Score: 5.5 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
linux linux_kernel * <built-in method update of dict object at 0x7d2364d68f80> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23a52f5340> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d2364d6ac80> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d2424508940> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d2364d69380> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d24246279c0> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d2364d6b140> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23a52f41c0> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d2364d6a9c0> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23bea20e80> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d242a79d700> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d23a52f7840> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d242a79fa00> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d24245085c0> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d23a52f7500> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d242450a400> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d23a52f7dc0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*

References

Notification
Message here