PT-2026-51758 · Linux · Linux Kernel
Published
2026-06-24
·
Updated
2026-06-24
·
CVE-2026-52943
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the network skbuff component where the
pskb carve inside header() and pskb carve inside nonlinear() functions copy the skb shared info header into a new buffer without calling net zcopy get() for the new shared information. This results in an unaccounted holder for the destructor arg pointer used in MSG ZEROCOPY skbs. Consequently, the reference count of uarg can be driven to zero prematurely, leading to a use-after-free condition on ubuf info msgzc while TX skbs still hold live pointers. This flaw allows an unprivileged local user to achieve full root privilege escalation on a default kernel configuration.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel