CVE-2026-53009
published 2026-06-24CVE-2026-53009: In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
ice: fix double-free of tx_buf skb
If ice_tso() or ice_tx_csum() fail, the error path in
ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points
to it and is marked as valid (ICE_TX_BUF_SKB).
'next_to_use' remains unchanged, so the potential problem will
likely fix itself when the next packet is transmitted and the tx_buf
gets overwritten. But if there is no next packet and the interface is
brought down instead, ice_clean_tx_ring() -> ice_unmap_and_free_tx_buf()
will find the tx_buf and free the skb for the second time.
The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error
path, so that ice_unmap_and_free_tx_buf().
Move the initialization of 'first' up, to ensure it's already valid in
case we hit the linearization error path.
The bug was spotted by AI while I had it looking for something else.
It also proposed an initial version of the patch.
I reproduced the bug and tested the fix by adding code to inject
failures, on a build with KASAN.
I looked for similar bugs in related Intel drivers and did not find any.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= d76a60ba7afb89523c88cf2ed3a044ce4180289e < 4c08fc2119ef0281cfa2cee007acf0a251be55f2 | 4c08fc2119ef0281cfa2cee007acf0a251be55f2 |
| linux | linux | >= d76a60ba7afb89523c88cf2ed3a044ce4180289e < 1a303baa715e6b78d6a406aaf335f87ff35acfcd | 1a303baa715e6b78d6a406aaf335f87ff35acfcd |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 7.0.9 ice ice_tso double free (WID-SEC-2026-2077)
vuldb·2026-06-27
CVE-2026-53009 [CRITICAL] Linux Kernel up to 7.0.9 ice ice_tso double free (WID-SEC-2026-2077)
A vulnerability was found in Linux Kernel up to 7.0.9. It has been classified as critical. This impacts the function ice_tso of the component ice. Performing a manipulation results in double free.
This vulnerability is identified as CVE-2026-53009. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but
ghsa_unreviewed·2026-06-24
CVE-2026-53009 In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but
In the Linux kernel, the following vulnerability has been resolved:
ice: fix double-free of tx_buf skb
If ice_tso() or ice_tx_csum() fail, the error path in
ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points
to it and is marked as valid (ICE_TX_BUF_SKB).
'next_to_use' remains unchanged, so the potential problem will
likely fix itself when the next packet is transmitted and the tx_buf
gets overwritten. But if there is no next packet and the interface is
brought down instead, ice_clean_tx_ring() -> ice_unmap_and_free_tx_buf()
will find the tx_buf and free the skb for the second time.
The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error
path, so that ice_unmap_and_free_tx_buf().
Move the initialization of 'first' up, to ensure it's already valid in
cas
Red Hat
kernel: ice: fix double-free of tx_buf skb
vendor_redhat·2026-06-24·CVSS 7.0
CVE-2026-53009 [HIGH] CWE-1341 kernel: ice: fix double-free of tx_buf skb
kernel: ice: fix double-free of tx_buf skb
A flaw was found in the Linux kernel's ice network driver. An error in the driver's handling of network packet transmission, specifically when ice_tso() or ice_tx_csum() functions fail, can lead to a double-free of a network buffer (skb). This occurs because a transmit buffer (tx_buf) may still point to an already freed buffer. If the network interface is subsequently brought down, this double-free can be triggered, potentially leading to a system crash or denial of service (DoS).
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Affected
Package: kernel (Red Hat Enterpri
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1a303baa715e6b78d6a406aaf335f87ff35acfcdhttps://git.kernel.org/stable/c/4c08fc2119ef0281cfa2cee007acf0a251be55f2https://access.redhat.com/security/cve/CVE-2026-53009https://bugzilla.redhat.com/show_bug.cgi?id=2492390https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53009.json
2026-06-24
Published