Lyrie
Critical CVE
CVSS 9.83 sources verified·1 min read
By Lyrie Threat Intelligence·6/28/2026

CRITICAL: CVE-2026-53151 (CVSS 9.8) — multiple products

CVE: CVE-2026-53151

CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: CRITICAL

Status: Critical advisory

Affected

_See vendor advisory_

Summary

In the Linux kernel, the following vulnerability has been resolved:

rxrpc: Fix the ACK parser to extract the SACK table for parsing

Fix modification of the received skbuff in rxrpc_input_soft_acks() and a

potential incorrect access of the buffer in a fragmented UDP packet (the

packet would probably have to be deliberately pre-generated as fragmented)

when AF_RXRPC tries to extract the contents of the SACK table by copying

out the contents of the SACK table into a buffer before attempting to parse

AF_RXRPC assumes that it can just call skb_condense() and then validly

access the SACK table from skb->data and that it will be a flat buffer -

but skb_condense() can silently fail to do anything under some

circumstances.

Note that whilst rxrpc_input_soft_acks() should be able to parse extended

ACKs, the rest of AF_RXRPC doesn't currently support that.

Further, there's then no need to call skb_condense() in rxrpc_input_ack(),

so don't.

Verified Sources

References

  • https://git.kernel.org/stable/c/224298450be5c04d2a6ea1c2a94669d7ebf65d00
  • https://git.kernel.org/stable/c/333b6d5bb9f87827ac2639c737bf9613dbae7253
  • https://git.kernel.org/stable/c/566c4c1244de50fbff1f89ff93c9d7b0fc256db4

_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._

Lyrie Verdict

A vulnerability of this severity is exactly what Lyrie's anti-rogue-AI defense is built for: continuous, autonomous monitoring that doesn't wait for human reaction time.

Validated sources

  1. [1]NVD
  2. [2]GitHub Advisory
  3. [3]MITRE