CVE-2026-52993
Severity CVSS v4.0:
Pending analysis
Type:
CWE-415
Double Free
Publication date:
24/06/2026
Last modified:
15/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
tipc: fix double-free in tipc_buf_append()<br />
<br />
tipc_msg_validate() can potentially reallocate the skb it is validating,<br />
freeing the old one. In tipc_buf_append(), it was being called with a<br />
pointer to a local variable which was a copy of the caller&#39;s skb<br />
pointer.<br />
<br />
If the skb was reallocated and validation subsequently failed, the error<br />
handling path would free the original skb pointer, which had already<br />
been freed, leading to double-free.<br />
<br />
Fix this by checking if head now points to a newly allocated reassembled<br />
skb. If it does, reassign *headbuf for later freeing operations.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.15 (including) | 5.10.258 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.209 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.175 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.141 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.91 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.33 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.10 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0274f24485fc38032d4093e463dc3ff5c7a667c9
- https://git.kernel.org/stable/c/1d5e589055880fae229e229e1929e087dbe08cf3
- https://git.kernel.org/stable/c/29940fff14110ca48c5ccc168d121665b51bb778
- https://git.kernel.org/stable/c/4d104882bc815d4ec666ace9155f5f52715879a6
- https://git.kernel.org/stable/c/4ee4deadaae7cb2e3d53af0fc889cf92a73413c0
- https://git.kernel.org/stable/c/a438975a6dcdbd70865978c021650d1485586f0b
- https://git.kernel.org/stable/c/d293ca716e7d5dffdaecaf6b9b2f857a33dc3d3a
- https://git.kernel.org/stable/c/d3556656c6daebf8def751c7e71d11dd0a180d24
- https://access.redhat.com/security/cve/CVE-2026-52993
- https://bugzilla.redhat.com/show_bug.cgi?id=2492437
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52993.json



