---
id: CVE-2026-53091
title: 'net: pull headers in qdisc_pkt_len_segs_init()'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: pull headers in qdisc_pkt_len_segs_init()

  Most ndo_start_xmit() methods expects headers of gso packets
  to be already in skb->head.

  net/core/tso.c users are parti…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= e876f208af18b074f800656e4d1b99da75b2135f <
    9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a
  - >-
    Linux >= e876f208af18b074f800656e4d1b99da75b2135f <
    7fb4c19670110f052c04e1ec1d2b953b9f4f57e4
  - Linux 3.16
published: '2026-06-24'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T12:04:34.429Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-53091'
references:
  - url: 'https://git.kernel.org/stable/c/9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a'
  - url: 'https://git.kernel.org/stable/c/7fb4c19670110f052c04e1ec1d2b953b9f4f57e4'
tags:
  - cve.org
epss: 0.00135
epssPercentile: 0.02419
ingestedAt: '2026-09-14T15:23:07.435Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: pull headers in qdisc_pkt_len_segs_init()

Most ndo_start_xmit() methods expects headers of gso packets
to be already in skb->head.

net/core/tso.c users are particularly at risk, because tso_build_hdr()
does a memcpy(hdr, skb->data, hdr_len);

qdisc_pkt_len_segs_init() already does a dissection of gso packets.

Use pskb_may_pull() instead of skb_header_pointer() to make
sure drivers do not have to reimplement this.

Some malicious packets could be fed, detect them so that we can
drop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.

## Affected

- `Linux >= e876f208af18b074f800656e4d1b99da75b2135f < 9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a`
- `Linux >= e876f208af18b074f800656e4d1b99da75b2135f < 7fb4c19670110f052c04e1ec1d2b953b9f4f57e4`
- `Linux 3.16`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
