CVE-2026-53236: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: tcp: restrict SO_ATTACH_FILTER to priv users This patch restricts the use of SO_ATTACH_FILTER (cBPF) on TCP sockets to users with CAP_NET_ADMIN capability. This blocks potential side-channel attack where an unprivileged application attaches a filter to leak TCP sequence/acknowledgment numbers.
Affected products
- Linux Linux Kernel: from 2.6.12.1, before 6.1.176 (fixed in 6.1.176); from 6.2, before 6.6.143 (fixed in 6.6.143); from 6.7, before 6.12.94 (fixed in 6.12.94); from 6.13, before 6.18.36 (fixed in 6.18.36); from 6.19, before 7.0.13 (fixed in 7.0.13); version 2.6.12 only; …
Published 2026-06-25. Last modified 2026-09-08.