IP Options Vulnerability in Linux Kernel
CVE-2026-53249
What is CVE-2026-53249?
The Linux kernel has addressed a significant vulnerability affecting the processing of Loose Source and Record Route (LSRR) and Strict Source and Record Route (SSRR) IP options. This issue allows unprivileged applications to manipulate packet routing, potentially exposing TCP Initial Sequence Numbers (ISNs) and other critical protocol information. By restricting these options to users with CAP_NET_RAW capability, the kernel mitigates the risk of packets being rerouted through compromised nodes, aligning with recommendations from RFC 7126. Although many network configurations already filter these options, some paths may still permit them, necessitating this crucial patch.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4cd6e9ed49347d3a2fdaaf07e32fb524756dddc2
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2a87c3e8f03ce655ed0ef500d64d5fd924ec3691
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 89343ff12b3178fc236fe531a3603e7c97c68278