PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72299 Linux CVE debrief

The Linux kernel has a vulnerability in the TIPC (Transparent Inter-Process Communication) subsystem. The issue arises from the `tipc_sk_enqueue` function, which holds a spinlock that protects the backlog queue but does not serialize against the socket owner consuming or purging `sk_receive_queue`. This can lead to a race condition where the `TIPC_DUMP_ALL` tracepoints in `tipc_sk_enqueue` may dump `sk_receive_queue` and dereference SKBs that the socket owner has already dequeued or freed.

Vendor
Linux
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-23
Advisory published
2026-08-15
Advisory updated
2026-08-23

Who should care

Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux-based systems that utilize the TIPC subsystem. Additionally, operators managing Linux-based infrastructure, platform administrators, vulnerability management teams, and security teams should be aware of this vulnerability and take necessary actions to mitigate its impact. This includes reviewing and applying patches, monitoring for potential exploits, and implementing compensating controls where necessary. The TIPC subsystem is used in various Linux kernel versions, and its usage can be widespread across different systems and deployments. Therefore, it is crucial for Linux kernel developers and maintainers to prioritize this vulnerability and ensure that affected systems are properly patched or mitigated. Linux distribution vendors should also provide updates and guidance to their users, while users of Linux-based systems should be aware of the potential risks and take steps to protect their systems. This may involve reviewing system configurations, monitoring for suspicious activity, and implementing additional security measures to prevent exploitation. By taking these steps, Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux-based systems can help mitigate the risks associated with this vulnerability and ensure the security and integrity of their systems. The vulnerability can be resolved by restricting the dumps to TIPC_DUMP_SK_BKLGQ, which matches the queue protected by the held spinlock. Linux kernel developers and maintainers should review the provided patches and apply them to the Linux kernel to fix the vulnerability. They should also monitor the Linux kernel and TIPC subsystem for any related security updates or advisories. Linux distribution vendors should provide updates and guidance to their users, while users of Linux-based systems should review their system configurations and implement compensating controls to limit the potential impact of the vulnerability. This may involve reviewing system logs, monitoring for suspicious activity, and implementing additional security measures to prevent exploitation. By taking these steps,

Technical summary

The vulnerability is caused by a race condition in the `tipc_sk_enqueue` function, which holds a spinlock that protects the backlog queue but does not serialize against the socket owner consuming or purging `sk_receive_queue`. This can lead to a situation where the `TIPC_DUMP_ALL` tracepoints in `tipc_sk_enqueue` may dump `sk_receive_queue` and dereference SKBs that the socket owner has already dequeued or freed. The issue can be resolved by restricting the dumps to `TIPC_DUMP_SK_BKLGQ`, which matches the queue protected by the held spinlock.

Defensive priority

High

Recommended defensive actions

  • Review and apply the provided patches to the Linux kernel to fix the vulnerability.
  • Monitor the Linux kernel and TIPC subsystem for any related security updates or advisories.
  • Consider implementing compensating controls, such as network segmentation or access controls, to limit the potential impact of the vulnerability.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.

Evidence notes

The vulnerability was reported by KASAN and involves a race condition in the TIPC subsystem of the Linux kernel. The issue is related to the `tipc_sk_enqueue` function and the `TIPC_DUMP_ALL` tracepoints. The CVE record and NVD entry provide details about the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72299 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72299

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72299 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72299

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/12876864f9de5fa6f611a30c6c17e405a773bf0a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/61a55fa24a5d737436018764a647fe5b6cb36371

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6acbbe54215d5f4251593000cff2bf51d6748713

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/acd7df8d955480a6f6e5bb809da67b1500cc3cf4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b9e100815f4b55e9ccaf6af9a3aba173eb13d381

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.