CVE-2026-53233 is a vulnerability in Linux Kernel
Published on June 25, 2026
netdev: fix double-free in netdev_nl_bind_rx_doit()
In the Linux kernel, the following vulnerability has been resolved:
netdev: fix double-free in netdev_nl_bind_rx_doit()
Sashiko flags that genlmsg_reply() always consumes the skb.
The error path calls nlmsg_free(rsp) so we can't jump directly
to it. Let's not unbind, just propagate the error to the user.
This is the typical way of handling genlmsg_reply() failures.
They shouldn't happen unless user does something silly like
calling the kernel with an already-full rcvbuf.
Products Associated with CVE-2026-53233
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 170aafe35cb98e0f3fbacb446ea86389fbce22ea and below e055ca9205d3eb6aec3e5fe4ecc18abbbf18c599 is affected.
- Version 170aafe35cb98e0f3fbacb446ea86389fbce22ea and below c299321bc6232770ce378d6fa6bc46004d2d7fdb is affected.
- Version 170aafe35cb98e0f3fbacb446ea86389fbce22ea and below 9b019376cbee10c4f9184d1745fa37d156e36f30 is affected.
- Version 170aafe35cb98e0f3fbacb446ea86389fbce22ea and below c849de7d8757a7af801fc4a4058f71d481d367f2 is affected.
- Version 6.12 is affected.
- Before 6.12 is unaffected.
- Version 6.12.94, <= 6.12.* is unaffected.
- Version 6.18.36, <= 6.18.* is unaffected.
- Version 7.0.13, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.