CVE-2026-52993 Linux 内核 TIPC 双重释放漏洞
影响攻击者可触发内核双重释放,可能导致提权或系统崩溃
该漏洞位于 Linux 内核 TIPC 子系统的 tipc_buf_append() 函数中。tipc_msg_validate() 在校验过程中可能重新分配 skb 并释放旧对象,而调用方仍持有旧指针,导致错误处理路径对已释放内存再次释放,形成双重释放。
影响范围
受影响范围为包含该缺陷代码的 Linux 内核版本,具体版本区间暂无公开信息。
漏洞详情
漏洞类型为内存双重释放(CWE-415)。成因是 tipc_buf_append() 将调用方 skb 指针的副本传给 tipc_msg_validate(),当校验触发 skb 重分配后校验失败,错误路径会释放已被释放的原始 skb。攻击者可通过构造特定 TIPC 报文触发该路径,进而破坏内核内存管理。
利用条件与风险
利用需能够向目标系统发送或注入 TIPC 报文,通常要求本地或相邻网络访问权限。成功利用可导致内核内存破坏,存在本地提权或拒绝服务风险。
修复建议
官方已通过检查 head 是否指向新分配的重组 skb 并重新赋值 *headbuf 修复该问题,建议升级到包含该补丁的内核版本。临时缓解可考虑禁用或限制 TIPC 模块的使用。
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix double-free in tipc_buf_append()
tipc_msg_validate() can potentially reallocate the skb it is validating,
freeing the old one. In tipc_buf_append(), it was being called with a
pointer to a local variable which was a copy of the caller’s skb
pointer.
If the skb was reallocated and validation subsequently failed, the error
handling path would free the original skb pointer, which had already
been freed, leading to double-free.
Fix this by checking if head now points to a newly allocated reassembled
skb. If it does, reassign *headbuf for later freeing operations.