[LTP] [PATCH] Add test for CVE 2026-53362
Andrea Cervesato
andrea.cervesato@suse.com
Thu Jul 23 14:24:14 CEST 2026
> Add test for memory corruption due to miscalculation of socket buffer
> size for fragmented packets with gaps.
>
> Signed-off-by: Martin Doucha <mdoucha@suse.cz>
> ---
>
> Bug reproducibility verified on affected kernels v6.4 and v6.12.
>
> runtest/cve | 1 +
> runtest/syscalls | 1 +
> .../kernel/syscalls/setsockopt/.gitignore | 1 +
> .../kernel/syscalls/setsockopt/setsockopt11.c | 171 ++++++++++++++++++
> 4 files changed, 174 insertions(+)
> create mode 100644 testcases/kernel/syscalls/setsockopt/setsockopt11.c
>
> diff --git a/runtest/cve b/runtest/cve
> index 3bbcfd6a2..99d84270b 100644
> --- a/runtest/cve
> +++ b/runtest/cve
> @@ -88,6 +88,7 @@ cve-2023-1829 tcindex01
> cve-2023-0461 setsockopt10
> cve-2023-31248 nft02
> cve-2023-52879 fanotify25
> +cve-2026-53362 setsockopt11
> # Tests below may cause kernel memory leak
> cve-2020-25704 perf_event_open03
> cve-2022-0185 fsconfig03
> diff --git a/runtest/syscalls b/runtest/syscalls
> index c84c32a6f..949ad7622 100644
> --- a/runtest/syscalls
> +++ b/runtest/syscalls
> @@ -1524,6 +1524,7 @@ setsockopt07 setsockopt07
> setsockopt08 setsockopt08
> setsockopt09 setsockopt09
> setsockopt10 setsockopt10
> +setsockopt11 setsockopt11
>
> settimeofday01 settimeofday01
> settimeofday02 settimeofday02
> diff --git a/testcases/kernel/syscalls/setsockopt/.gitignore b/testcases/kernel/syscalls/setsockopt/.gitignore
> index 5c05290a5..58cc82d9c 100644
> --- a/testcases/kernel/syscalls/setsockopt/.gitignore
> +++ b/testcases/kernel/syscalls/setsockopt/.gitignore
> @@ -8,3 +8,4 @@
> /setsockopt08
> /setsockopt09
> /setsockopt10
> +/setsockopt11
> diff --git a/testcases/kernel/syscalls/setsockopt/setsockopt11.c b/testcases/kernel/syscalls/setsockopt/setsockopt11.c
> new file mode 100644
> index 000000000..5f09291b3
> --- /dev/null
> +++ b/testcases/kernel/syscalls/setsockopt/setsockopt11.c
> @@ -0,0 +1,171 @@
> +// SPDX-License-Identifier: GPL-2.0-or-later
> +/*
> + * Copyright (C) 2026 SUSE LLC
> + * Original reproducer by Massimiliano Oldani
> + * Simplified LTP port: Martin Doucha <mdoucha@suse.com>
> + */
> +
> +/*
> + * CVE 2026-53362
> + *
> + * Test for vulnerability in socket buffer size calculation for fragmented
> + * UDP packets with gaps. Reproducer based on:
> + * https://github.com/sgkdev/ipv6_frag_escape
> + *
> + * Memory corruption fixed in kernel v7.2:
> + * 736b380e28d0 ("ipv6: account for fraggap on the paged allocation path")
We can add an Algorithm section to make the test easier to read.
* [Algorithm]
*
* - Fill pipe[0] with a known pattern (0x42) ("canary" page).
* - Splice pages into a corked socket so the skb references pipe[0]'s page.
* - Close the socket -> the corruption causes the page refcount to drop
* too low -> the page appears free while pipe[0] still owns it.
* - Pollute all free memory with 0xBD (inverse of 0x42).
* - Read pipe[0] back. If any byte changed, the page was reallocated
* while the pipe still held it -> the bug is confirmed.
> + /* Splice input pipe buffer page into socket */
> + memset(buf, 0, TEST_MSGSIZE);
> + buf[TEST_MSGSIZE - 6] = 1;
> + SAFE_WRITE(SAFE_WRITE_ALL, pipefds[1][1], buf, TEST_MSGSIZE);
> + splice(pipefds[1][0], NULL, sockfd, NULL, TEST_MSGSIZE, SPLICE_F_MORE);
SAFE_SPLICE() here.
> +static void cleanup(void)
> +{
> + int i;
> +
> + for (i = 0; i < PIPE_COUNT; i++) {
> + if (pipefds[i][0] >= 0) {
This should be != -1 according to static definition and the SAFE_CLOSE()
bahavior in the test (it sets to -1).
> + SAFE_CLOSE(pipefds[i][0]);
> + SAFE_CLOSE(pipefds[i][1]);
> + }
> + }
> +
> + if (sockfd >= 0)
And here as well.
The rest looks good to me.
--
Andrea Cervesato
SUSE QE Automation Engineer Linux
andrea.cervesato@suse.com
More information about the ltp
mailing list