From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3AD6D312837 for ; Wed, 24 Jun 2026 16:34:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782318896; cv=none; b=JCYXjI21qJW4EehJUK506qoqWAq58174uPsUlzz8t+0+iTHQmQpPOYSjsI75666rDq/MlTq1DIh/GSNtXm/Vu9HWr1WR5ZCwm55OQFueVs0hLLf5BEqt+PjB3dQDMrDCaKv+zk4XnLLqf/asuOwODuh1ISuYMPaEU8IDaBXc5xc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782318896; c=relaxed/simple; bh=F3QQzsB3fWgRpHyJvP5MEq7qmxh0+JyUZlE6tfvrVE0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=J2Pe1dlphEYA7qJK15iHhf4PB7ElGeiSEjkZnmqi5iA69UNJR7zxTEsxKe1TgqTeMqNo+exNFT94b9jiDQSy7y1yGXojHAX66alFLn+BSRJOSL43vwTJ96pred+E15zHMr6RwfDqGSrs7YBsebRPVTb19G2SkpdNTMFS6On5TbE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=S4TBl789; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="S4TBl789" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 80B261F000E9; Wed, 24 Jun 2026 16:34:54 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1782318895; bh=aTxpvnkUh/okK+6L+VMzYlbuIz1GpHWRmn+8rYJ8T7Q=; h=From:To:Cc:Subject:Date:Reply-To; b=S4TBl789suxBQ78uSnk06XllKp5wS5FmdEwzF+/nyGwiilCdkMZupmRysLwX1Gm+I fSWb0N48vKYxBhB+LhFpe7E/HVRV9uNNXRcXp19htcOPQsr4fF0ZjcbYQV7zbwY1pY RU/WDhAz5muZVllIOGkt/7DTHa9GQYQD9WGcBEj8= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-53009: ice: fix double-free of tx_buf skb Date: Wed, 24 Jun 2026 17:30:33 +0100 Message-ID: <2026062449-CVE-2026-53009-4fef@gregkh> X-Mailer: git-send-email 2.54.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2804; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=V5ouFEX2LER9pBWe1aOnLl734AtKq4zCr3+paB6YGxs=; b=owGbwMvMwCRo6H6F97bub03G02pJDFk2rH8FNhwL2pMZcvhd7W3PW0c28jxeGydwsShvx3aOe t8NK3JjO2JZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAiX0QY5scnxfBZrdZxfhpx MlRBPiN/Un3pcob5yb8mRQh2OcV+Ut5ZebqifIdj0/HTAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). 'next_to_use' remains unchanged, so the potential problem will likely fix itself when the next packet is transmitted and the tx_buf gets overwritten. But if there is no next packet and the interface is brought down instead, ice_clean_tx_ring() -> ice_unmap_and_free_tx_buf() will find the tx_buf and free the skb for the second time. The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error path, so that ice_unmap_and_free_tx_buf(). Move the initialization of 'first' up, to ensure it's already valid in case we hit the linearization error path. The bug was spotted by AI while I had it looking for something else. It also proposed an initial version of the patch. I reproduced the bug and tested the fix by adding code to inject failures, on a build with KASAN. I looked for similar bugs in related Intel drivers and did not find any. The Linux kernel CVE team has assigned CVE-2026-53009 to this issue. Affected and fixed versions =========================== Issue introduced in 4.17 with commit d76a60ba7afb89523c88cf2ed3a044ce4180289e and fixed in 7.0.10 with commit 4c08fc2119ef0281cfa2cee007acf0a251be55f2 Issue introduced in 4.17 with commit d76a60ba7afb89523c88cf2ed3a044ce4180289e and fixed in 7.1 with commit 1a303baa715e6b78d6a406aaf335f87ff35acfcd Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-53009 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/ethernet/intel/ice/ice_txrx.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/4c08fc2119ef0281cfa2cee007acf0a251be55f2 https://git.kernel.org/stable/c/1a303baa715e6b78d6a406aaf335f87ff35acfcd