PT-2026-51758 · Linux · Linux Kernel

Published

2026-06-24

·

Updated

2026-06-24

·

CVE-2026-52943

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the network skbuff component where the pskb carve inside header() and pskb carve inside nonlinear() functions copy the skb shared info header into a new buffer without calling net zcopy get() for the new shared information. This results in an unaccounted holder for the destructor arg pointer used in MSG ZEROCOPY skbs. Consequently, the reference count of uarg can be driven to zero prematurely, leading to a use-after-free condition on ubuf info msgzc while TX skbs still hold live pointers. This flaw allows an unprivileged local user to achieve full root privilege escalation on a default kernel configuration.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-52943

Affected Products

Linux Kernel