KernelScan.io

CRITICAL Introduced in 4.15

tipc BufAppend DoubleFree

CVE-2026-52993

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations.

02

Engine v0.3.0

Risk summary

A double-free vulnerability in the TIPC protocol's fragment reassembly path can be triggered by sending specially crafted fragmented TIPC messages with invalid truesize ratios. This can lead to kernel memory corruption, potentially enabling denial of service or, in more complex exploitation scenarios, privilege escalation or information disclosure. The bug is reachable from the network without authentication in configurations where TIPC is used.

Affectednet/tipc/msg.c (TIPC networking subsystem)

Vulnerability analysis

The vulnerability is a double-free in tipc_buf_append() in net/tipc/msg.c. When the last fragment of a reassembled TIPC message is received, tipc_msg_validate() is called to check the truesize/length ratio. If the ratio is invalid, tipc_msg_validate() internally frees the original skb and allocates a new, smaller one, updating its local 'head' pointer. However, tipc_buf_append() passed a local copy of the head pointer (not the caller's *headbuf pointer), so after tipc_msg_validate() returns failure, the error handling path calls kfree_skb(*headbuf), which still points to the already-freed original skb — resulting in a double-free. The fix checks whether 'head' has changed after tipc_msg_validate() returns (indicating reallocation occurred), and if so, updates *headbuf to point to the newly allocated skb so the subsequent error-path free operates on the correct buffer. The attack surface is network-reachable: an attacker can send crafted TIPC fragmented packets with a truesize/length ratio that triggers the reallocation path followed by validation failure, triggering the double-free in the kernel. Exploitation requires high complexity due to heap layout dependencies needed to turn the double-free into a useful primitive.

03

BranchIntroducedFixed inPatch commit
6.64.156.6.1410274f24485fc
5.104.155.10.258a438975a6dcd
5.154.155.15.2094ee4deadaae7
6.124.156.12.914d104882bc81
7.04.157.0.1029940fff1411
6.184.156.18.331d5e58905588
6.14.156.1.175d3556656c6da
mainline4.157.1d293ca716e7d