Junglewise Threat Intelligence

CVE-2026-52943: Linux Kernel use-after-free in skbuff pskb_carve helpers

CVE-2026-52943 · Severity: info · CVSS 7.8 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to gain full administrative (root) control over the system. The issue occurs when the system handles certain types of high-efficiency network data transfers, leading to a memory error. An attacker can exploit this flaw to bypass security boundaries and compromise the entire operating system.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's net/core/skbuff.c within the pskb_carve_inside_header() and pskb_carve_inside_nonlinear() helper functions. These functions use memcpy() to copy skb_shared_info but fail to call net_zcopy_get() to increment the reference count for MSG_ZEROCOPY skbs. This leads to a premature free of the ubuf_info_msgzc structure while active TX skbs still hold pointers to it. A local unprivileged attacker can trigger this condition to achieve reliable root privilege escalation. Patches have been released across multiple stable kernel branches to ensure net_zcopy_get() is called during the carve operations.

Affected products

  • Linux Linux Kernel Fixed in various stable branches including 2.6.x, 4.x, 5.x, 6.x, and 7.x

Timeline

  • 2026-05-26: other: Vulnerability fixed in source code
  • 2026-06-24: advisory: NVD publication date

References

Related threats