CRITICAL Introduced in 4.15
tipc BufAppend DoubleFree
CVE-2026-52993
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.0HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations.
02KernelScan AI Analysis
Risk summary
A double-free vulnerability in the TIPC protocol's fragment reassembly path can be triggered by sending specially crafted fragmented TIPC messages with invalid truesize ratios. This can lead to kernel memory corruption, potentially enabling denial of service or, in more complex exploitation scenarios, privilege escalation or information disclosure. The bug is reachable from the network without authentication in configurations where TIPC is used.
Vulnerability analysis
The vulnerability is a double-free in tipc_buf_append() in net/tipc/msg.c. When the last fragment of a reassembled TIPC message is received, tipc_msg_validate() is called to check the truesize/length ratio. If the ratio is invalid, tipc_msg_validate() internally frees the original skb and allocates a new, smaller one, updating its local 'head' pointer. However, tipc_buf_append() passed a local copy of the head pointer (not the caller's *headbuf pointer), so after tipc_msg_validate() returns failure, the error handling path calls kfree_skb(*headbuf), which still points to the already-freed original skb — resulting in a double-free. The fix checks whether 'head' has changed after tipc_msg_validate() returns (indicating reallocation occurred), and if so, updates *headbuf to point to the newly allocated skb so the subsequent error-path free operates on the correct buffer. The attack surface is network-reachable: an attacker can send crafted TIPC fragmented packets with a truesize/length ratio that triggers the reallocation path followed by validation failure, triggering the double-free in the kernel. Exploitation requires high complexity due to heap layout dependencies needed to turn the double-free into a useful primitive.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.6 | 4.15 | 6.6.141 | 0274f24485fc |
| 5.10 | 4.15 | 5.10.258 | a438975a6dcd |
| 5.15 | 4.15 | 5.15.209 | 4ee4deadaae7 |
| 6.12 | 4.15 | 6.12.91 | 4d104882bc81 |
| 7.0 | 4.15 | 7.0.10 | 29940fff1411 |
| 6.18 | 4.15 | 6.18.33 | 1d5e58905588 |
| 6.1 | 4.15 | 6.1.175 | d3556656c6da |
| mainline | 4.15 | 7.1 | d293ca716e7d |