First published 3 September 2026 (Pre-Notification)
CVSS:3.1: 7.8 (High)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
A security vulnerability has been found in the Linux kernel used in IGEL OS. This affects the following product versions:
-
IGEL OS 12
-
IGEL OS 11
Details
The IPv6 subsystem in the Linux Kernel is affected by a privilege escalation issue (CVE-2026-53362, high). A local non-privileged user can exploit it via a fabricated local UDP datagram.
CISA lists this vulnerability as exploited in the wild in its Known Exploited Vulnerabilities Catalog (KEV).
Update Instructions
-
OS 12: Upgrade the OS 12 Base System app to version 12.10.1 or 12.8.4 LTS as soon as these are available on the IGEL APP Portal.
-
OS 11: IGEL OS 11 reached End of Maintenance in June 2026. To ensure continued access to security updates and support, we recommend migrating to IGEL OS 12.
References
-
CVE-2026-53362: https://www.cve.org/CVERecord?id=CVE-2026-53362
-
CISA Known Exploited Vulnerabilities Catalog (KEV): https://www.cisa.gov/known-exploited-vulnerabilities-catalog