CVE-2026-52993: Double-Free Vulnerability in Linux Kernel TIPC Module
Vulnerability ID: CVE-2026-52993
CVSS Score: 9.8
Published: 2026-06-24
A critical double-free vulnerability exists in the Transparent Inter-Process Communication (TIPC) module of the Linux kernel, specifically within the fragment reassembly implementation in tipc_buf_append(). This vulnerability can be triggered locally or remotely to cause kernel heap corruption, leading to local privilege escalation or denial of service.
TL;DR
A double-free flaw in the Linux kernel's TIPC module allows local privilege escalation to root or remote kernel heap corruption via crafted network packets.
⚠️ Exploit Status: WEAPONIZED
Technical Details
- CWE ID: CWE-415
- Attack Vector: Network (UDP Port 6118 or Ethernet Bearer)
- CVSS v3.1 Score: 9.8 (Critical)
- Exploit Status: PoC / Weaponized
- Primary Impact: Local Privilege Escalation / Remote Heap Corruption
- CWE Name: Double Free
Affected Systems
- Linux Kernel
-
Linux Kernel: >= 4.15, < 5.10.258 (Fixed in:
5.10.258) -
Linux Kernel: >= 5.11, < 5.15.209 (Fixed in:
5.15.209) -
Linux Kernel: >= 5.16, < 6.1.175 (Fixed in:
6.1.175) -
Linux Kernel: >= 6.2, < 6.6.141 (Fixed in:
6.6.141) -
Linux Kernel: >= 6.7, < 6.12.91 (Fixed in:
6.12.91) -
Linux Kernel: >= 6.13, < 6.18.33 (Fixed in:
6.18.33) -
Linux Kernel: >= 6.19, < 7.0.10 (Fixed in:
7.0.10)
Code Analysis
Commit: d293ca7
tipc: fix double-free of headbuf in tipc_buf_append
Exploit Details
- GitHub: Functional local privilege escalation and remote heap corruption exploit against kernel version 6.6.140
Mitigation Strategies
- Blacklist the TIPC kernel module to prevent it from loading into memory.
- Restrict unprivileged user namespace creation to prevent loopback configuration.
- Configure firewall rules to drop unauthorized UDP traffic on port 6118.
Remediation Steps:
- Identify the current running kernel version using 'uname -r'.
- Update the system packages using the distribution package manager (e.g., 'apt update && apt upgrade' or 'dnf update').
- Reboot the system to load the patched kernel version.
- Verify that the loaded kernel version is equal to or higher than the patched releases (e.g., 5.10.258, 5.15.209, 6.1.175, 6.6.141, 6.12.91, 6.18.33, or 7.0.10).
References
- Linux Kernel Stable Patch
- Red Hat CVE-2026-52993 Security Advisory
- CaptainAI Labs LPE Exploit Repository
Read the full report for CVE-2026-52993 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)