A double-free vulnerability tracked as CVE-2026-52993 was disclosed in the Linux kernel's Transparent Inter-Process Communication (TIPC) subsystem, specifically in tipc_buf_append() within net/tipc/msg.c. The bug occurs when tipc_msg_validate() reallocates a socket buffer, frees the original buffer, and subsequent error handling frees the stale pointer again, creating conditions for system instability, denial of service, and possible arbitrary code execution in some scenarios. The flaw affects code introduced in kernel 4.15, and the Linux kernel CVE team said it was fixed across multiple stable and mainline branches.
Red Hat rated the issue Important with a CVSS v3 score of 7.0 and said fixes were released through security errata for Red Hat Enterprise Linux 8, 9, and 10 kernel packages. At the time of Red Hat's advisory, RHEL 9 kernel-rt remained affected, while RHEL 6 and 7 kernel variants were not impacted because the vulnerable code was absent. Upstream maintainers advised organizations to update to the latest stable kernel releases rather than cherry-picking individual patches.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2026:47017 to fix CVE-2026-52993 in Red Hat Enterprise Linux 10 kernel packages. The issue remained listed as affecting RHEL 9 kernel-rt at the time of the entry.
Red Hat shipped fixes for CVE-2026-52993 for Red Hat Enterprise Linux 8 kernel via RHSA-2026:45115 and RHEL 8 kernel-rt via RHSA-2026:45116. Red Hat rated the flaw Important severity.
The Linux kernel CVE announcement documented fixes for CVE-2026-52993 in versions 5.10.258, 5.15.209, 6.1.175, 6.6.141, 6.12.91, 6.18.33, 7.0.10, and 7.1. The fix updates pointer handling so later frees use the correct reallocated skb.
The Linux kernel CVE team assigned CVE-2026-52993 to a double-free vulnerability in the TIPC subsystem's tipc_buf_append(). The bug can occur when tipc_msg_validate() reallocates an skb and later error handling frees the stale pointer again.
Red Hat released RHSA-2026:49212 to address CVE-2026-52993 in Red Hat Enterprise Linux 9 kernel packages. Red Hat continued to list RHEL 9 kernel-rt as affected.
The vulnerable code path for CVE-2026-52993 was introduced in Linux kernel 4.15 via commit d618d09a68e4eed7a435beb2e355250f6f40664a. The flaw affects the TIPC subsystem's tipc_buf_append() handling after skb reallocation.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.