DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-52993: CVE-2026-52993: Double-Free Vulnerability in Linux Kernel TIPC Module

CVE-2026-52993: Double-Free Vulnerability in Linux Kernel TIPC Module

Vulnerability ID: CVE-2026-52993
CVSS Score: 9.8
Published: 2026-06-24

A critical double-free vulnerability exists in the Transparent Inter-Process Communication (TIPC) module of the Linux kernel, specifically within the fragment reassembly implementation in tipc_buf_append(). This vulnerability can be triggered locally or remotely to cause kernel heap corruption, leading to local privilege escalation or denial of service.

TL;DR

A double-free flaw in the Linux kernel's TIPC module allows local privilege escalation to root or remote kernel heap corruption via crafted network packets.


⚠️ Exploit Status: WEAPONIZED

Technical Details

  • CWE ID: CWE-415
  • Attack Vector: Network (UDP Port 6118 or Ethernet Bearer)
  • CVSS v3.1 Score: 9.8 (Critical)
  • Exploit Status: PoC / Weaponized
  • Primary Impact: Local Privilege Escalation / Remote Heap Corruption
  • CWE Name: Double Free

Affected Systems

  • Linux Kernel
  • Linux Kernel: >= 4.15, < 5.10.258 (Fixed in: 5.10.258)
  • Linux Kernel: >= 5.11, < 5.15.209 (Fixed in: 5.15.209)
  • Linux Kernel: >= 5.16, < 6.1.175 (Fixed in: 6.1.175)
  • Linux Kernel: >= 6.2, < 6.6.141 (Fixed in: 6.6.141)
  • Linux Kernel: >= 6.7, < 6.12.91 (Fixed in: 6.12.91)
  • Linux Kernel: >= 6.13, < 6.18.33 (Fixed in: 6.18.33)
  • Linux Kernel: >= 6.19, < 7.0.10 (Fixed in: 7.0.10)

Code Analysis

Commit: d293ca7

tipc: fix double-free of headbuf in tipc_buf_append

Exploit Details

  • GitHub: Functional local privilege escalation and remote heap corruption exploit against kernel version 6.6.140

Mitigation Strategies

  • Blacklist the TIPC kernel module to prevent it from loading into memory.
  • Restrict unprivileged user namespace creation to prevent loopback configuration.
  • Configure firewall rules to drop unauthorized UDP traffic on port 6118.

Remediation Steps:

  1. Identify the current running kernel version using 'uname -r'.
  2. Update the system packages using the distribution package manager (e.g., 'apt update && apt upgrade' or 'dnf update').
  3. Reboot the system to load the patched kernel version.
  4. Verify that the loaded kernel version is equal to or higher than the patched releases (e.g., 5.10.258, 5.15.209, 6.1.175, 6.6.141, 6.12.91, 6.18.33, or 7.0.10).

References


Read the full report for CVE-2026-52993 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)