CVE-2026-53009
Reported by Linux · Published June 24, 2026
In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). 'next_to_use' remains unchanged, so the potential problem will likely fix itself when the next packet is transmitted and the tx_buf gets overwritten. But if there is no next packet and the interface is brought down instead, ice_clean_tx_ring() -> ice_unmap_and_free_tx_buf() will find the tx_buf and free the skb for the second time. The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error path, so that ice_unmap_and_free_tx_buf(). Move the initialization of 'first' up, to ensure it's already valid in case we hit the linearization error path. The bug was spotted by AI while I had it looking for something else. It also proposed an initial version of the patch. I reproduced the bug and tested the fix by adding code to inject failures, on a build with KASAN. I looked for similar bugs in related Intel drivers and did not find any.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | d76a60ba7afb89523c88cf2ed3a044ce4180289e, d76a60ba7afb89523c88cf2ed3a044ce4180289e |
| Linux | Linux | 4.17, 0, 7.0.10 |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 10 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| linux | linux_kernel | 4.17, 4.17, 4.17 |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| chainguard | linux-gcp-6.18 | 0, 0, 0 |
| Red Hat | Red Hat Enterprise Linux 10 | 0:6.12.0-211.37.1.el10_2, 0:6.12.0-211.37.1.el10_2, 0:6.12.0-211.37.1.el10_2 |
| Linux | Linux | 7.1, d76a60ba7afb89523c88cf2ed3a044ce4180289e, 4.17 |
| chainguard | linux-qemu-6.18 | 0, 0, 0 |
| Red Hat | Red Hat Enterprise Linux 9 |
Timeline
- Jun 24, 2026 CVE Published
- Jun 25, 2026 Coalition ESS Score
- Jun 26, 2026 EPSS Score
- Jul 22, 2026 Distribution Patch
- Jul 22, 2026 Security Advisory
- Jul 27, 2026 Distribution Patch
- Aug 7, 2026 EPSS Score
- Aug 12, 2026 Distribution Patch
- Aug 12, 2026 Security Advisory
- Aug 12, 2026 CVE Updated
- Aug 12, 2026 Distribution Patch
- Aug 12, 2026 Security Advisory
References
- https://access.redhat.com/security/cve/CVE-2026-53009 vdb
- RHBZ#2492390 issue
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53009.json url
- https://access.redhat.com/errata/RHSA-2026:42919 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:54246 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:54247 vendor-advisory