---
id: CVE-2026-43011
title: 'net/x25: Fix potential double free of skb'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net/x25: Fix potential double free of skb

  When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at
  line 48 and returns 1 (error).
  This error propagates ba…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    5d0aa038a90b30c9bedde0c41c1fdcd98ecb16e9
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    3f5e3005984645bf5bd129c6b13149879580b1fb
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    f782dd382203b2a8c4552a628431b7de65a19a7b
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    143d4fa68ae9efb83b0c55b12cc7f0d03732a2b1
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    524371398d8463ea7e101fce2cbf3915645d1730
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    fa1dbc93530b34fab0da9862426fe9c918c74dc0
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    c87dd137c0dad07cc55f98181ff380b0c23d2878
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    d10a26aa4d072320530e6968ef945c8c575edf61
  - Linux 2.6.12
published: '2026-05-01'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:48:21.398Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-43011'
references:
  - url: 'https://git.kernel.org/stable/c/5d0aa038a90b30c9bedde0c41c1fdcd98ecb16e9'
  - url: 'https://git.kernel.org/stable/c/3f5e3005984645bf5bd129c6b13149879580b1fb'
  - url: 'https://git.kernel.org/stable/c/f782dd382203b2a8c4552a628431b7de65a19a7b'
  - url: 'https://git.kernel.org/stable/c/143d4fa68ae9efb83b0c55b12cc7f0d03732a2b1'
  - url: 'https://git.kernel.org/stable/c/524371398d8463ea7e101fce2cbf3915645d1730'
  - url: 'https://git.kernel.org/stable/c/fa1dbc93530b34fab0da9862426fe9c918c74dc0'
  - url: 'https://git.kernel.org/stable/c/c87dd137c0dad07cc55f98181ff380b0c23d2878'
  - url: 'https://git.kernel.org/stable/c/d10a26aa4d072320530e6968ef945c8c575edf61'
tags:
  - cve.org
epss: 0.00868
epssPercentile: 0.57021
ingestedAt: '2026-09-08T15:33:26.989Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net/x25: Fix potential double free of skb

When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at
line 48 and returns 1 (error).
This error propagates back through the call chain:

x25_queue_rx_frame returns 1
    |
    v
x25_state3_machine receives the return value 1 and takes the else
branch at line 278, setting queued=0 and returning 0
    |
    v
x25_process_rx_frame returns queued=0
    |
    v
x25_backlog_rcv at line 452 sees queued=0 and calls kfree_skb(skb)
again

This would free the same skb twice. Looking at x25_backlog_rcv:

net/x25/x25_in.c:x25_backlog_rcv() {
    ...
    queued = x25_process_rx_frame(sk, skb);
    ...
    if (!queued)
        kfree_skb(skb);
}

## Affected

- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5d0aa038a90b30c9bedde0c41c1fdcd98ecb16e9`
- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3f5e3005984645bf5bd129c6b13149879580b1fb`
- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f782dd382203b2a8c4552a628431b7de65a19a7b`
- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 143d4fa68ae9efb83b0c55b12cc7f0d03732a2b1`
- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 524371398d8463ea7e101fce2cbf3915645d1730`
- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fa1dbc93530b34fab0da9862426fe9c918c74dc0`
- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c87dd137c0dad07cc55f98181ff380b0c23d2878`
- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d10a26aa4d072320530e6968ef945c8c575edf61`
- `Linux 2.6.12`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
