VDB

CVE-2026-53009

CVE-2026-53009 PUBLISHED CVSS 7.8 HIGH

Reported by Linux · Published June 24, 2026

In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). 'next_to_use' remains unchanged, so the potential problem will likely fix itself when the next packet is transmitted and the tx_buf gets overwritten. But if there is no next packet and the interface is brought down instead, ice_clean_tx_ring() -> ice_unmap_and_free_tx_buf() will find the tx_buf and free the skb for the second time. The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error path, so that ice_unmap_and_free_tx_buf(). Move the initialization of 'first' up, to ensure it's already valid in case we hit the linearization error path. The bug was spotted by AI while I had it looking for something else. It also proposed an initial version of the patch. I reproduced the bug and tested the fix by adding code to inject failures, on a build with KASAN. I looked for similar bugs in related Intel drivers and did not find any.

Risk Scores

CVSS 3.1
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
LinuxLinuxd76a60ba7afb89523c88cf2ed3a044ce4180289e, d76a60ba7afb89523c88cf2ed3a044ce4180289e
LinuxLinux4.17, 0, 7.0.10
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
linuxlinux_kernel4.17, 4.17, 4.17
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 8
chainguardlinux-gcp-6.180, 0, 0
Red HatRed Hat Enterprise Linux 100:6.12.0-211.37.1.el10_2, 0:6.12.0-211.37.1.el10_2, 0:6.12.0-211.37.1.el10_2
LinuxLinux7.1, d76a60ba7afb89523c88cf2ed3a044ce4180289e, 4.17
chainguardlinux-qemu-6.180, 0, 0
Red HatRed Hat Enterprise Linux 9

Timeline

  • Jun 24, 2026 CVE Published
  • Jun 25, 2026 Coalition ESS Score
  • Jun 26, 2026 EPSS Score
  • Jul 22, 2026 Distribution Patch
  • Jul 22, 2026 Security Advisory
  • Jul 27, 2026 Distribution Patch
  • Aug 7, 2026 EPSS Score
  • Aug 12, 2026 Distribution Patch
  • Aug 12, 2026 Security Advisory
  • Aug 12, 2026 CVE Updated
  • Aug 12, 2026 Distribution Patch
  • Aug 12, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›