news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-53236

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
7.0 High
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.12%
Risk score
1.6
Published
2026-06-25
Status
Published

In the Linux kernel, the following vulnerability has been resolved: tcp: restrict SO_ATTACH_FILTER to priv users This patch restricts the use of SO_ATTACH_FILTER (cBPF) on TCP sockets to users with CAP_NET_ADMIN capability. This blocks potential side-channel attack where an unprivileged application attaches a filter to leak TCP sequence/acknowledgment numbers. A flaw was found in the Linux kernel's handling of TCP sockets. An unprivileged application can exploit this vulnerability by attaching a Berkeley Packet Filter (BPF) using the SO_ATTACH_FILTER option. This allows the application to conduct a side-channel attack, leading to the leakage of sensitive TCP sequence and acknowledgment numbers. This information disclosure could potentially be used to aid further attacks.

Weaknesses

CWE-266

Coverage 3

Advisories and references