In the Linux kernel, the following vulnerability has been resolved:
ice: fix double-free of tx_buf skb
If ice_tso() or ice_tx_csum() fail, the error path in
ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points
to it and is marked as valid (ICE_TX_BUF_SKB).
'next_to_use' remains unchanged, so the potential problem will
likely fix itself when the next packet is transmitted and the tx_buf
gets overwritten. But if there is no next packet and the interface is
brought down instead, ice_clean_tx_ring() -> ice_unmap_and_free_tx_buf()
will find the tx_buf and free the skb for the second time.
The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error
path, so that ice_unmap_and_free_tx_buf().
Move the initialization of 'first' up, to ensure it's already valid in
case we hit the linearization error path.
The bug was spotted by AI while I had it looking for something else.
It also proposed an initial version of the patch.
I reproduced the bug and tested the fix by adding code to inject
failures, on a build with KASAN.
I looked for similar bugs in related Intel drivers and did not find any.
References
| Link | Resource |
|---|---|
| https://git.kernel.org/stable/c/1a303baa715e6b78d6a406aaf335f87ff35acfcd | Patch |
| https://git.kernel.org/stable/c/4c08fc2119ef0281cfa2cee007acf0a251be55f2 | Patch |
| https://access.redhat.com/errata/RHSA-2026:42919 | |
| https://access.redhat.com/security/cve/CVE-2026-53009 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2492390 | Third Party Advisory |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53009.json | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
22 Jul 2026, 12:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
14 Jul 2026, 18:44
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Linux linux Kernel
Redhat enterprise Linux Redhat Linux |
|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* |
|
| CWE | CWE-415 | |
| References | () https://git.kernel.org/stable/c/1a303baa715e6b78d6a406aaf335f87ff35acfcd - Patch | |
| References | () https://git.kernel.org/stable/c/4c08fc2119ef0281cfa2cee007acf0a251be55f2 - Patch | |
| References | () https://access.redhat.com/security/cve/CVE-2026-53009 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2492390 - Third Party Advisory | |
| References | () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53009.json - Third Party Advisory |
08 Jul 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-416 |
30 Jun 2026, 03:20
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-1341 | |
| References |
|
28 Jun 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
24 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-24 17:17
Updated : 2026-07-22 12:18
NVD link : CVE-2026-53009
Mitre link : CVE-2026-53009
CVE.ORG link : CVE-2026-53009
JSON object : View
Products Affected
redhat
- enterprise_linux
linux
- linux_kernel
