CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-52993

CVE-2026-52993: Double-Free Vulnerability in Linux Kernel TIPC Module

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 6, 2026·7 min read·3 visits

Executive Summary (TL;DR)

A double-free flaw in the Linux kernel's TIPC module allows local privilege escalation to root or remote kernel heap corruption via crafted network packets.

A critical double-free vulnerability exists in the Transparent Inter-Process Communication (TIPC) module of the Linux kernel, specifically within the fragment reassembly implementation in `tipc_buf_append()`. This vulnerability can be triggered locally or remotely to cause kernel heap corruption, leading to local privilege escalation or denial of service.

Vulnerability Overview

The Transparent Inter-Process Communication (TIPC) module in the Linux kernel is designed for high-performance cluster communication. It operates as a network layer protocol, allowing nodes within a cluster to communicate efficiently over raw Ethernet, UDP, or other media. The attack surface is exposed directly to incoming network traffic when a TIPC bearer is configured and active, making it highly critical.

Within this framework, message fragmentation is handled by tipc_buf_append() in net/tipc/msg.c. This function is responsible for gathering incoming individual fragment buffers, tracking their sequence, and reassembling them into a coherent message structure before passing the completed buffer up the stack for validation.

The vulnerability, designated as CVE-2026-52993, is a critical double-free vulnerability (CWE-415) located within this reassembly process. It is rated with a CVSS v3.1 score of 9.8, indicating maximum severity. Unauthenticated remote attackers can exploit this flaw by sending specifically structured UDP or raw Ethernet frames, while local attackers can use it to achieve local privilege escalation.

Root Cause Analysis

The root cause of CVE-2026-52993 lies in how memory references are managed during the reassembly of fragmented messages. In tipc_buf_append(), the reassembled socket buffer head is tracked via a double pointer argument headbuf. A local pointer variable head is initialized to the value of *headbuf. When the final fragment (LAST_FRAGMENT) is processed, the function invokes tipc_msg_validate(&head) to verify the structure and headers of the newly reassembled packet.

Within tipc_msg_validate(), the kernel evaluates whether the socket buffer is using memory efficiently. If the buffer's physical footprint (truesize) is disproportionately large compared to its logical data length (len)—specifically if the ratio truesize / roundup_len(len) is equal to or greater than 4—the function reallocates a new, smaller buffer to prevent memory fragmentation. It then copies the existing data to the new buffer, deallocates the original socket buffer, and updates its local pointer argument to point to the new buffer.

Because tipc_buf_append() passes the address of its local variable head (&head) to tipc_msg_validate(), only the local variable head is updated when a reallocation occurs. The caller's tracking pointer, *headbuf, remains pointing to the old, deallocated socket buffer. If validation subsequently fails (for example, due to an invalid TIPC header version), tipc_buf_append() aborts and executes its error cleanup handler, calling kfree_skb(*headbuf). This causes the kernel to free the already-deallocated buffer a second time, triggering a double-free condition.

Code Analysis

To understand the precise vulnerability mechanics, we must analyze the vulnerable code path in net/tipc/msg.c and compare it with the official patch. The following code block illustrates the vulnerability where the local variable is passed to the validation routine without updating the primary tracking pointer.

// Vulnerable Code Path
int tipc_buf_append(struct sk_buff **headbuf, struct sk_buff **buf)
{
    // ...
    struct sk_buff *head = *headbuf; // Local copy of the caller's headbuf pointer
    // ...
    if (fragid == LAST_FRAGMENT) {
        TIPC_SKB_CB(head)->validated = 0;
        // The address of the local variable 'head' is passed here
        if (unlikely(!tipc_msg_validate(&head)))
            goto err; // Jumps to error cleanup without updating *headbuf
        // ...
    }
    // ...
err:
    kfree_skb(*buf);
    kfree_skb(*headbuf); // DOUBLE FREE: *headbuf still points to the old, freed skb
}

To address this issue, the patch introduces a check immediately following the validation failure. If the validation fails, the code determines whether the local head pointer has changed from the original *headbuf due to reallocation. If it has, *headbuf is updated with the new pointer value before jumping to the error label. This ensures that the cleanup routine deallocates the newly allocated buffer and does not reference the freed memory.

// Patched Code Path (Commit d293ca716e7d5dffdaecaf6b9b2f857a33dc3d3a)
int tipc_buf_append(struct sk_buff **headbuf, struct sk_buff **buf)
{
    // ...
    struct sk_buff *head = *headbuf;
    // ...
    if (fragid == LAST_FRAGMENT) {
        TIPC_SKB_CB(head)->validated = 0;
        if (unlikely(!tipc_msg_validate(&head))) {
            // Propagate the new pointer back to the caller's reference if reallocated
            if (head != *headbuf)
                *headbuf = head;
            goto err;
        }
        // ...
    }
    // ...
}

This fix is complete because it guarantees that any reallocation within tipc_msg_validate() is synchronized with the caller's state tracking pointer, neutralizing the possibility of referencing a stale address during cleanup.

Exploitation Methodology

The exploitation of CVE-2026-52993 involves triggering the double-free condition to manipulate the SLUB allocator's metadata and gain control of kernel memory. An attacker can initiate this sequence either locally or remotely. The primary requirement is that the TIPC stack must be active and configured with a functional bearer.

In the first phase of the attack, the adversary establishes a TIPC link and floods the victim node with a precise sequence of tiny fragments. These small frames populate the page fragment lists, causing the truesize of the master socket buffer to grow linearly while its logical length remains low. This forces the ratio check to evaluate to true, triggering reallocation and deallocation of the initial buffer. By crafting the first fragment to contain an invalid TIPC version header, the attacker guarantees that validation will fail immediately after reallocation.

Once the double-free occurs, the SLUB allocator's freelist pointer is corrupted, typically resulting in a circular reference loop. The attacker can then reclaim this block by allocating structures such as files_struct or user_key_payload. By writing forged metadata over the overlapping memory, the attacker can redirect function pointers (such as f_op->flush) to kernel routines like override_creds or manipulate the user-space credentials directly, establishing full root privilege escalation.

Impact Assessment

The impact of CVE-2026-52993 is highly severe, threatening both system availability and integrity. Because the TIPC module can process incoming frames from raw Ethernet interfaces or UDP port 6118 without prior authentication, a remote attacker can exploit this flaw to cause immediate kernel panic and denial of service across cluster nodes.

On systems with local access, the vulnerability acts as a highly reliable mechanism for local privilege escalation. By abusing the overlapping slab allocations, an unprivileged user can hijack kernel-space execution flow. In environments where Supervisor Mode Access Prevention (SMAP) is disabled or not supported, this technique allows the kernel to execute structures pointing directly to user-controlled memory space, facilitating seamless privilege transition to uid 0.

The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H reflects this danger. No user interaction or privileges are required to reach the vulnerable code path over the network, and the integrity, confidentiality, and availability impacts are all rated as high. This makes rapid remediation a priority for affected deployments.

Mitigation & Remediation

Remediation requires updating the Linux kernel to a patched release. The fix has been backported to all major stable kernel branches, including 5.10.258, 5.15.209, 6.1.175, 6.6.141, 6.12.91, 6.18.33, and 7.0.10. Systems should be rebooted into a patched kernel version immediately.

If immediate patching is not possible, several temporary mitigations can be applied to block the exploit vectors. If the TIPC protocol is not actively required, the module should be blacklisted to prevent it from loading into memory. This can be configured by executing echo 'install tipc /bin/true' | sudo tee /etc/modprobe.d/tipc.conf and unloading any active instances using sudo rmmod tipc.

In environments where TIPC is necessary but remote exposure must be restricted, firewall rules should be configured to drop incoming packets on UDP port 6118 unless they originate from highly trusted, authenticated peer nodes. Additionally, restricting the creation of unprivileged user namespaces (sysctl -w kernel.unprivileged_userns_clone=0) can limit a local attacker's ability to configure the loopback interfaces and bearer channels required to execute the LPE exploit chain.

Official Patches

Linux KernelOfficial patch for main stable branches
Red HatRed Hat Security Advisory RHSA-2026:45115

Fix Analysis (1)

Technical Appendix

CVSS Score
9.8/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Systems

Linux Kernel

Affected Versions Detail

Product
Affected Versions
Fixed Version
Linux Kernel
Linux
>= 4.15, < 5.10.2585.10.258
Linux Kernel
Linux
>= 5.11, < 5.15.2095.15.209
Linux Kernel
Linux
>= 5.16, < 6.1.1756.1.175
Linux Kernel
Linux
>= 6.2, < 6.6.1416.6.141
Linux Kernel
Linux
>= 6.7, < 6.12.916.12.91
Linux Kernel
Linux
>= 6.13, < 6.18.336.18.33
Linux Kernel
Linux
>= 6.19, < 7.0.107.0.10
AttributeDetail
CWE IDCWE-415
Attack VectorNetwork (UDP Port 6118 or Ethernet Bearer)
CVSS v3.1 Score9.8 (Critical)
Exploit StatusPoC / Weaponized
Primary ImpactLocal Privilege Escalation / Remote Heap Corruption
CWE NameDouble Free

MITRE ATT&CK Mapping

T1068Exploitation for Privilege Escalation
Privilege Escalation
T1210Exploitation of Remote Services
Lateral Movement
T1190Exploitation of Public-Facing Application
Initial Access
CWE-415
Double Free

The product frees memory resources twice, which can lead to write-what-where conditions, heap corruption, and arbitrary code execution.

Known Exploits & Detection

GitHubFunctional local privilege escalation and remote heap corruption exploit against kernel version 6.6.140

References & Sources

  • [1]Linux Kernel Stable Patch
  • [2]Red Hat CVE-2026-52993 Security Advisory
  • [3]CaptainAI Labs LPE Exploit Repository

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•18 minutes ago•CVE-2026-102600
7.5

CVE-2026-102600: Unhandled Runtime Exception via Unsafe Prototype Lookup in @socket.io/cluster-engine

A critical Denial of Service (DoS) vulnerability exists in @socket.io/cluster-engine before version 0.1.1. Unauthenticated remote attackers can crash the server process by supplying inherited prototype property names as session identifiers.

Alon Barad
Alon Barad
1 views•6 min read
•about 1 hour ago•CVE-2026-96747
5.0

CVE-2026-96747: Local Unix Domain Socket SSRF via KMS Endpoint Manipulation in PyMongo

A vulnerability in the Client-Side Field-Level Encryption (CSFLE) component of the MongoDB Python Driver (PyMongo) allows an attacker with database write access to trigger local Unix domain socket connections. By manipulating the Key Management Service (KMS) endpoint configuration inside the key vault collection to end with a '.sock' extension, an attacker forces the application to perform a Server-Side Request Forgery (SSRF) against internal Unix domain sockets.

Alon Barad
Alon Barad
4 views•6 min read
•about 2 hours ago•CVE-2026-72137
9.8

CVE-2026-72137: Double Free in Linux Kernel XFRM NAT Keepalive

CVE-2026-72137 is a critical double-free vulnerability in the Linux kernel's XFRM (IPsec) subsystem. The vulnerability occurs when the kernel attempts to send NAT keepalive packets over UDP. Under specific transmission failure conditions, both the downstream networking stack and the upstream keepalive dispatcher attempt to free the same socket buffer (sk_buff) structure, leading to kernel memory corruption, denial of service, or potential local privilege escalation.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 2 hours ago•CVE-2026-96748
8.3

CVE-2026-96748: Host Injection Vulnerability in PyMongo Connection String Parsing

A critical host injection vulnerability exists in PyMongo's connection string parser prior to version 4.18.2. The parser globally decodes percent-encoded characters in the host portion before splitting on delimiters, allowing attackers to inject arbitrary servers into the database client's connection pool.

Amit Schendel
Amit Schendel
5 views•7 min read
•about 3 hours ago•CVE-2026-96749
8.4

CVE-2026-96749: Heap Out-of-Bounds Write in MongoDB PyMongo BSON Encoder

An integer overflow vulnerability exists in PyMongo's bundled C extension (bson/buffer.c) when serializing abnormally large documents. Due to compiler optimizations utilizing standard C Undefined Behavior rules, memory overflow validation checks are completely removed during compilation, enabling an attacker to trigger a heap-based out-of-bounds write.

Alon Barad
Alon Barad
6 views•6 min read
•about 4 hours ago•CVE-2026-102827
8.1

CVE-2026-102827: Command and Argument Injection Bypass in simple-git via Option Abbreviation

CVE-2026-102827 is an argument injection bypass vulnerability in the node.js simple-git package where the default blockUnsafeOperationsPlugin fails to detect abbreviated Git command options. Attackers can bypass validations using prefixes like --receive-p or --exe, which native Git subsequently expands to dangerous options, leading to remote command execution.

Alon Barad
Alon Barad
6 views•7 min read