IM
IronMonkey Threat Research

CVE-2026-53249 MEDIUM

Published: 2026-06-25 | Last Modified: 2026-09-08 | Status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options This patch restricts setting Loose Source and Record Route (LSRR) and Strict Source and Record Route (SSRR) IP options to users with CAP_NET_RAW capability. This prevents unprivileged applications from forcing packets to route through attacker-controlled nodes to leak TCP ISN and possibly other protocol information. While LSRR and SSRR are commonly filtered in many network environments, they may still be supported and forwarded along some network paths. RFC 7126 (Recommendations on Filtering of IPv4 Packets Containing IPv4 Options) recommend to drop these options in 4.3 and 4.4.

CVSS Metrics

Base Score: 5.5 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
linux linux_kernel * <built-in method update of dict object at 0x7d23af257f00> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23a59074c0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23a5907800> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23a5311440> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23a5906280> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23a5905400> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23a5906a40> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23beb844c0> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23bea97c00> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23a5905d80> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23beb87e80> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23bea94680> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d23be9fc040> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d23bea96700> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d23bea97d40> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d23beb86f80> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d23beb86880> Operating System
linux linux_kernel 7.1 <built-in method update of dict object at 0x7d23bea962c0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*

References

Notification
Message here