CVE-2026-52993

In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

14 Jul 2026, 19:44

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/0274f24485fc38032d4093e463dc3ff5c7a667c9 - () https://git.kernel.org/stable/c/0274f24485fc38032d4093e463dc3ff5c7a667c9 - Patch
References () https://git.kernel.org/stable/c/1d5e589055880fae229e229e1929e087dbe08cf3 - () https://git.kernel.org/stable/c/1d5e589055880fae229e229e1929e087dbe08cf3 - Patch
References () https://git.kernel.org/stable/c/29940fff14110ca48c5ccc168d121665b51bb778 - () https://git.kernel.org/stable/c/29940fff14110ca48c5ccc168d121665b51bb778 - Patch
References () https://git.kernel.org/stable/c/4d104882bc815d4ec666ace9155f5f52715879a6 - () https://git.kernel.org/stable/c/4d104882bc815d4ec666ace9155f5f52715879a6 - Patch
References () https://git.kernel.org/stable/c/4ee4deadaae7cb2e3d53af0fc889cf92a73413c0 - () https://git.kernel.org/stable/c/4ee4deadaae7cb2e3d53af0fc889cf92a73413c0 - Patch
References () https://git.kernel.org/stable/c/a438975a6dcdbd70865978c021650d1485586f0b - () https://git.kernel.org/stable/c/a438975a6dcdbd70865978c021650d1485586f0b - Patch
References () https://git.kernel.org/stable/c/d293ca716e7d5dffdaecaf6b9b2f857a33dc3d3a - () https://git.kernel.org/stable/c/d293ca716e7d5dffdaecaf6b9b2f857a33dc3d3a - Patch
References () https://git.kernel.org/stable/c/d3556656c6daebf8def751c7e71d11dd0a180d24 - () https://git.kernel.org/stable/c/d3556656c6daebf8def751c7e71d11dd0a180d24 - Patch
References () https://access.redhat.com/security/cve/CVE-2026-52993 - () https://access.redhat.com/security/cve/CVE-2026-52993 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2492437 - () https://bugzilla.redhat.com/show_bug.cgi?id=2492437 - Third Party Advisory
References () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52993.json - () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52993.json - Third Party Advisory
CWE CWE-415
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

30 Jun 2026, 03:20

Type Values Removed Values Added
CWE CWE-763
References
  • () https://access.redhat.com/security/cve/CVE-2026-52993 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2492437 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52993.json -

28 Jun 2026, 08:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

24 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-24 17:17

Updated : 2026-07-15 01:16


NVD link : CVE-2026-52993

Mitre link : CVE-2026-52993

CVE.ORG link : CVE-2026-52993


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-415

Double Free

CWE-763

Release of Invalid Pointer or Reference