A length miscalculation in Linux IPv6 fragmentation enables container escape
Red Hat has published a bulletin for CVE-2026-53362, an out-of-bounds write in the Linux kernel’s IPv6 fragmentation path that lets a local user escape a container and bypass SELinux. Apply the patched kernel, or disable unprivileged user namespaces in the meantime.