cbcvebase.
CVE-2026-52993
published 2026-06-24

CVE-2026-52993: In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate…

PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.35%
28.1th percentile
In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= d618d09a68e4eed7a435beb2e355250f6f40664a < a438975a6dcdbd70865978c021650d1485586f0ba438975a6dcdbd70865978c021650d1485586f0b
linuxlinux>= d618d09a68e4eed7a435beb2e355250f6f40664a < 4ee4deadaae7cb2e3d53af0fc889cf92a73413c04ee4deadaae7cb2e3d53af0fc889cf92a73413c0
linuxlinux>= d618d09a68e4eed7a435beb2e355250f6f40664a < d3556656c6daebf8def751c7e71d11dd0a180d24d3556656c6daebf8def751c7e71d11dd0a180d24
linuxlinux>= d618d09a68e4eed7a435beb2e355250f6f40664a < 0274f24485fc38032d4093e463dc3ff5c7a667c90274f24485fc38032d4093e463dc3ff5c7a667c9
linuxlinux>= d618d09a68e4eed7a435beb2e355250f6f40664a < 4d104882bc815d4ec666ace9155f5f52715879a64d104882bc815d4ec666ace9155f5f52715879a6
linuxlinux>= d618d09a68e4eed7a435beb2e355250f6f40664a < 1d5e589055880fae229e229e1929e087dbe08cf31d5e589055880fae229e229e1929e087dbe08cf3
linuxlinux>= d618d09a68e4eed7a435beb2e355250f6f40664a < 29940fff14110ca48c5ccc168d121665b51bb77829940fff14110ca48c5ccc168d121665b51bb778
linuxlinux>= d618d09a68e4eed7a435beb2e355250f6f40664a < d293ca716e7d5dffdaecaf6b9b2f857a33dc3d3ad293ca716e7d5dffdaecaf6b9b2f857a33dc3d3a
linuxlinux_kernel
linuxlinux_kernel>= 4.15 < 5.10.2585.10.258
linuxlinux_kernel>= 5.11 < 5.15.2095.15.209
linuxlinux_kernel>= 5.16 < 6.1.1756.1.175
linuxlinux_kernel>= 6.13 < 6.18.336.18.33
linuxlinux_kernel>= 6.19 < 7.0.107.0.10
linuxlinux_kernel>= 6.2 < 6.6.1416.6.141
linuxlinux_kernel>= 6.7 < 6.12.916.12.91
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.1HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.