CVE-2026-43451

MEDIUM EPSS 2.4%
Published May 8, 20261mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 8, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path nfqnl_recv_verdict() calls find_dequeue_entry() to remove the queue entry from the queue data structures, taking ownership of the entry. For PF_BRIDGE packets, it then calls nfqa_parse_bridge() to parse VLAN attributes. If nfqa_parse_bridge() returns an error (e.g. NFQA_VLAN present but NFQA_VLAN_TCI missing), the function returns immediately without freeing the dequeued entry or its sk_buff. This leaks the nf_queue_entry, its associated sk_buff, and all held references (net_device refcounts, struct net refcount). Repeated triggering exhausts kernel memory. Fix this by dropping the entry via nfqnl_reinject() with NF_DROP verdict on the error path, consistent with other error handling in this file.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-401

Affected Products 10

VendorProductVersionRange
linuxlinux_kernel*≥4.7  –  <5.10.253
linuxlinux_kernel*≥5.11  –  <5.15.203
linuxlinux_kernel*≥5.16  –  <6.1.167
linuxlinux_kernel*≥6.2  –  <6.6.130
linuxlinux_kernel*≥6.7  –  <6.12.78
linuxlinux_kernel*≥6.13  –  <6.18.19
linuxlinux_kernel*≥6.19  –  <6.19.9
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any

References 8

  • git.kernel.org https://git.kernel.org/stable/c/0b18d1b834ab5a5009be70b530f978d7989e445b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/208669df703a25a601f45822b10c413f258bf275
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/47b1c5d1b0944aa88299f55a846fabaefc756982
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9853d94b82d303fc4ac37d592a23a154096ecd41
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a907bea273b60d3e604ec4e8e1f6c49954805794
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b38d2b4603fd3dda24eb8b3dd81c18a0930be97b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cf4a4df38d1747e06fc54f9879bd7a6f4178032f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f1ba83755d81c6fc66ac7acd723d238f974091e9
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/0b18d1b834ab5a5009be70b530f978d7989e445b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/208669df703a25a601f45822b10c413f258bf275
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/47b1c5d1b0944aa88299f55a846fabaefc756982
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9853d94b82d303fc4ac37d592a23a154096ecd41
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a907bea273b60d3e604ec4e8e1f6c49954805794
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b38d2b4603fd3dda24eb8b3dd81c18a0930be97b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cf4a4df38d1747e06fc54f9879bd7a6f4178032f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f1ba83755d81c6fc66ac7acd723d238f974091e9
    Patch