๐Ÿ” CVE Alert

CVE-2026-43451

UNKNOWN 0.0

netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path nfqnl_recv_verdict() calls find_dequeue_entry() to remove the queue entry from the queue data structures, taking ownership of the entry. For PF_BRIDGE packets, it then calls nfqa_parse_bridge() to parse VLAN attributes. If nfqa_parse_bridge() returns an error (e.g. NFQA_VLAN present but NFQA_VLAN_TCI missing), the function returns immediately without freeing the dequeued entry or its sk_buff. This leaks the nf_queue_entry, its associated sk_buff, and all held references (net_device refcounts, struct net refcount). Repeated triggering exhausts kernel memory. Fix this by dropping the entry via nfqnl_reinject() with NF_DROP verdict on the error path, consistent with other error handling in this file.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published May 8, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
8d45ff22f1b43249f0cf1baafe0262ca10d1666e < a907bea273b60d3e604ec4e8e1f6c49954805794 8d45ff22f1b43249f0cf1baafe0262ca10d1666e < 0b18d1b834ab5a5009be70b530f978d7989e445b 8d45ff22f1b43249f0cf1baafe0262ca10d1666e < b38d2b4603fd3dda24eb8b3dd81c18a0930be97b 8d45ff22f1b43249f0cf1baafe0262ca10d1666e < 47b1c5d1b0944aa88299f55a846fabaefc756982 8d45ff22f1b43249f0cf1baafe0262ca10d1666e < cf4a4df38d1747e06fc54f9879bd7a6f4178032f 8d45ff22f1b43249f0cf1baafe0262ca10d1666e < 9853d94b82d303fc4ac37d592a23a154096ecd41 8d45ff22f1b43249f0cf1baafe0262ca10d1666e < 208669df703a25a601f45822b10c413f258bf275 8d45ff22f1b43249f0cf1baafe0262ca10d1666e < f1ba83755d81c6fc66ac7acd723d238f974091e9
Linux / Linux
4.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a907bea273b60d3e604ec4e8e1f6c49954805794 git.kernel.org: https://git.kernel.org/stable/c/0b18d1b834ab5a5009be70b530f978d7989e445b git.kernel.org: https://git.kernel.org/stable/c/b38d2b4603fd3dda24eb8b3dd81c18a0930be97b git.kernel.org: https://git.kernel.org/stable/c/47b1c5d1b0944aa88299f55a846fabaefc756982 git.kernel.org: https://git.kernel.org/stable/c/cf4a4df38d1747e06fc54f9879bd7a6f4178032f git.kernel.org: https://git.kernel.org/stable/c/9853d94b82d303fc4ac37d592a23a154096ecd41 git.kernel.org: https://git.kernel.org/stable/c/208669df703a25a601f45822b10c413f258bf275 git.kernel.org: https://git.kernel.org/stable/c/f1ba83755d81c6fc66ac7acd723d238f974091e9