cbcvebase.
CVE-2026-43011
published 2026-05-01

CVE-2026-43011: In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it…

PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.59%
44.3th percentile
In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates back through the call chain: x25_queue_rx_frame returns 1 | v x25_state3_machine receives the return value 1 and takes the else branch at line 278, setting queued=0 and returning 0 | v x25_process_rx_frame returns queued=0 | v x25_backlog_rcv at line 452 sees queued=0 and calls kfree_skb(skb) again This would free the same skb twice. Looking at x25_backlog_rcv: net/x25/x25_in.c:x25_backlog_rcv() { ... queued = x25_process_rx_frame(sk, skb); ... if (!queued) kfree_skb(skb); }

Affected

75 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5d0aa038a90b30c9bedde0c41c1fdcd98ecb16e95d0aa038a90b30c9bedde0c41c1fdcd98ecb16e9
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3f5e3005984645bf5bd129c6b13149879580b1fb3f5e3005984645bf5bd129c6b13149879580b1fb
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f782dd382203b2a8c4552a628431b7de65a19a7bf782dd382203b2a8c4552a628431b7de65a19a7b
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 143d4fa68ae9efb83b0c55b12cc7f0d03732a2b1143d4fa68ae9efb83b0c55b12cc7f0d03732a2b1
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 524371398d8463ea7e101fce2cbf3915645d1730524371398d8463ea7e101fce2cbf3915645d1730
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fa1dbc93530b34fab0da9862426fe9c918c74dc0fa1dbc93530b34fab0da9862426fe9c918c74dc0
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c87dd137c0dad07cc55f98181ff380b0c23d2878c87dd137c0dad07cc55f98181ff380b0c23d2878
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d10a26aa4d072320530e6968ef945c8c575edf61d10a26aa4d072320530e6968ef945c8c575edf61
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 2.6.12.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1686.1.168
linuxlinux_kernel>= 6.13 < 6.18.226.18.22
linuxlinux_kernel>= 6.19 < 6.19.126.19.12

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.