CVE-2026-52993
tipc: fix double-free in tipc_buf_append()
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
24 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix double-free in tipc_buf_append()
tipc_msg_validate() can potentially reallocate the skb it is validating,
freeing the old one. In tipc_buf_append(), it was being called with a
pointer to a local variable which was a copy of the caller's skb
pointer.
If the skb was reallocated and validation subsequently failed, the error
handling path would free the original skb pointer, which had already
been freed, leading to double-free.
Fix this by checking if head now points to a newly allocated reassembled
skb. If it does, reassign *headbuf for later freeing operations.
Affected products
Linux · LinuxWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://git.kernel.org/stable/c/0274f24485fc38032d4093e463dc3ff5c7a667c9https://git.kernel.org/stable/c/1d5e589055880fae229e229e1929e087dbe08cf3https://git.kernel.org/stable/c/29940fff14110ca48c5ccc168d121665b51bb778https://git.kernel.org/stable/c/4d104882bc815d4ec666ace9155f5f52715879a6https://git.kernel.org/stable/c/4ee4deadaae7cb2e3d53af0fc889cf92a73413c0https://git.kernel.org/stable/c/a438975a6dcdbd70865978c021650d1485586f0bhttps://git.kernel.org/stable/c/d293ca716e7d5dffdaecaf6b9b2f857a33dc3d3ahttps://git.kernel.org/stable/c/d3556656c6daebf8def751c7e71d11dd0a180d24