DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Frag Gap (CVE-2026-53362, CVE-2026-53366)

Quality: 8/10 Relevance: 9/10

Summary

This writeup analyzes Fraggap, a Linux kernel vulnerability (CVE-2026-53362 and CVE-2026-53366) in the UDPv6 corking path that enables a 15-byte out-of-bounds write in skb_shared_info. It explains the root cause in frag gap accounting, the exploitation sequence, and the patch that fixes fraggap handling, with a detailed timeline through mid-2026. The article is a thorough technical breakdown suitable for developers, security professionals, and SMB IT admins using Linux servers.

🚀 Service construit par Johan Denoyer