{"id":"CVE-2026-53091","title":"net: pull headers in qdisc_pkt_len_segs_init()","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: pull headers in qdisc_pkt_len_segs_init()\n\nMost ndo_start_xmit() methods expects headers of gso packets\nto be already in skb->head.\n\nnet/core/tso.c users are parti…","severity":"high","cvss":8.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= e876f208af18b074f800656e4d1b99da75b2135f < 9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a","Linux >= e876f208af18b074f800656e4d1b99da75b2135f < 7fb4c19670110f052c04e1ec1d2b953b9f4f57e4","Linux 3.16"],"published":"2026-06-24","updated":"2026-09-14","sourceUpdated":"2026-09-14T12:04:34.429Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-53091","references":[{"url":"https://git.kernel.org/stable/c/9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a"},{"url":"https://git.kernel.org/stable/c/7fb4c19670110f052c04e1ec1d2b953b9f4f57e4"}],"tags":["cve.org"],"epss":0.00135,"epssPercentile":0.02419,"ingestedAt":"2026-09-14T15:23:07.435Z","slug":"CVE-2026-53091","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: pull headers in qdisc_pkt_len_segs_init()\n\nMost ndo_start_xmit() methods expects headers of gso packets\nto be already in skb->head.\n\nnet/core/tso.c users are particularly at risk, because tso_build_hdr()\ndoes a memcpy(hdr, skb->data, hdr_len);\n\nqdisc_pkt_len_segs_init() already does a dissection of gso packets.\n\nUse pskb_may_pull() instead of skb_header_pointer() to make\nsure drivers do not have to reimplement this.\n\nSome malicious packets could be fed, detect them so that we can\ndrop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.\n\n## Affected\n\n- `Linux >= e876f208af18b074f800656e4d1b99da75b2135f < 9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a`\n- `Linux >= e876f208af18b074f800656e4d1b99da75b2135f < 7fb4c19670110f052c04e1ec1d2b953b9f4f57e4`\n- `Linux 3.16`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":46.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}