CVE-2026-52935 Details
Description
In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: do not reuse an in-progress partial send espintcp keeps a single in-flight transmit in ctx->partial. Before building a new sk_msg, espintcp_sendmsg() first tries to flush that state through espintcp_push_msgs(). For blocking callers, espintcp_push_msgs() may return success even when the previous partial send is still pending. espintcp_sendmsg() would then reinitialize emsg->skmsg and reuse ctx->partial while the old transfer still owns that state. Do not rebuild the send message when ctx->partial is still in progress. If espintcp_push_msgs() returns with emsg->len still set, fail the new send instead of overwriting the live partial state. This is a memory-safety fix: reusing the live partial-send state can leave a stale offset attached to a new sk_msg and lead to an out-of- bounds read in the send path. tcp_sendmsg_locked() already handles waiting for send buffer memory, so the fix here is just to preserve espintcp's one-message-at-a-time transmit state.
A vulnerability in the Linux kernel's ESPINTCP implementation can lead to memory safety issues. The problem arises because ESPINTCP maintains a single in-flight transmission state in 'ctx->partial'. When a new message is being prepared, the function 'espintcp_sendmsg()' attempts to clear the existing partial state by calling 'espintcp_push_msgs()'. However, for blocking callers, this function might incorrectly indicate that it's safe to proceed, even if the previous send is still pending. As a result, 'espintcp_sendmsg()' could overwrite the ongoing transfer's state, leading to potential out-of-bounds reads in the send path. This vulnerability affects the Linux kernel stable tree.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version can be found in the Linux kernel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/1777ceac4bea5e568a5ad44b7f9bb219c1db21b6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/37487d55bf3300e3d2c1368da5c2bd3e3834ea4f | kernel.org | Patch |
| https://git.kernel.org/stable/c/6564e9c7af7e1dc7bfe7f3093b728abe484d7630 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8c6c691bf062dc0753a139a4ab8cb92a70fcf8f3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/aa82a078f70f7ff88ba7d1017134e79d1ac140f2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ba21439302db9a82fe4edbed1e38a97271529421 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c381039ade2e161ab08c0eda73c4f8b9a7115928 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f9b38a8fbfa07f1deaf7ee1eb38fa8b21ea13990 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.6, < 5.10.259 >= 5.11, < 5.15.210 >= 5.16, < 6.1.176 >= 6.2, < 6.6.143 >= 6.7, < 6.12.94 >= 6.13, < 6.18.36 >= 6.19, < 7.0.13 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 7.1 rc5 7.1 rc6 7.1 rc7 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jun 28, 2026 | CVE Modified | kernel.org |
| Jun 24, 2026 | New CVE Received | kernel.org |