← All CVEs

CVE-2026-53221

critical · 9.8

In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() In vti6_tnl_lookup(), when an exact match for a tunnel fails, the code falls back to searching for wildcard tunnels: - Tunnels matching the packet's local address, with any remote address wildcard remote). - Tunnels matching the packet's remote address, with any local address (wildcard local). However, vti6 stores all these different types of tunnels in the same hash table (ip6n->tnls_r_l) prone to hash collisions. The bug is that the fallback search loops in vti6_tnl_lookup() were missing checks to ensure that the candidate tunnel actually has a wildcard address.

9.8
CVSS
0.5%
EPSS (exploit prob.)
43rd
EPSS percentile
2026-06-25
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
linuxlinux_kernel>= 3.19, < 5.10.259
linuxlinux_kernel>= 5.11, < 5.15.210
linuxlinux_kernel>= 5.16, < 6.1.176
linuxlinux_kernel>= 6.2, < 6.6.143
linuxlinux_kernel>= 6.7, < 6.12.94
linuxlinux_kernel>= 6.13, < 6.18.36
linuxlinux_kernel>= 6.19, < 7.0.13
linuxlinux_kernel7.1
linuxlinux_kernel7.1
linuxlinux_kernel7.1
linuxlinux_kernel7.1
linuxlinux_kernel7.1
linuxlinux_kernel7.1
linuxlinux_kernel7.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-53221