CVE-2026-53263
Received Received - Intake
6LoWPAN Multicast Context Address Compression Off-by-One in Linux Kernel

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: kernel.org

Description
In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix off-by-one in multicast context address compression The second memcpy in lowpan_iphc_mcast_ctx_addr_compress() uses &data[1] as destination and &ipaddr->s6_addr[11] as source, but both should be offset by one: &data[2] and &ipaddr->s6_addr[12] respectively. This off-by-one has two consequences: 1. data[1] is overwritten with s6_addr[11], corrupting the RIID field in the compressed multicast address 2. data[5] is never written, so uninitialized kernel stack memory is transmitted over the network via lowpan_push_hc_data(), leaking kernel stack contents The correct inline data layout must match what the decompression function lowpan_uncompress_multicast_ctx_daddr() expects: data[0..1] = s6_addr[1..2] (flags/scope + RIID) data[2..5] = s6_addr[12..15] (group ID) Also zero-initialize the data array as a defensive measure against similar bugs in the future.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-25
AI Q&A
2026-06-25
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Mitigation Strategies

The vulnerability is fixed by correcting the off-by-one error in the multicast context address compression in the Linux kernel's 6lowpan implementation.

Immediate mitigation steps include updating the Linux kernel to a version that contains the fix for this issue.

Additionally, zero-initializing the data array as a defensive measure is part of the fix to prevent similar bugs.

Executive Summary

This vulnerability is an off-by-one error in the Linux kernel's 6lowpan multicast context address compression function. Specifically, the function lowpan_iphc_mcast_ctx_addr_compress() incorrectly copies data with an offset error, causing one byte of data to overwrite the RIID field and another byte to remain unwritten.

As a result, uninitialized kernel stack memory is leaked over the network because data that should have been written is not, and corrupted data is transmitted instead.

Impact Analysis

This vulnerability can lead to the leakage of uninitialized kernel stack memory over the network. This means sensitive kernel memory contents could be exposed to attackers, potentially revealing confidential information or aiding further attacks.

Additionally, the corruption of the RIID field in the compressed multicast address could cause network communication issues or unexpected behavior in the 6lowpan protocol.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53263. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart