CVE-2026-43451 Details
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path nfqnl_recv_verdict() calls find_dequeue_entry() to remove the queue entry from the queue data structures, taking ownership of the entry. For PF_BRIDGE packets, it then calls nfqa_parse_bridge() to parse VLAN attributes. If nfqa_parse_bridge() returns an error (e.g. NFQA_VLAN present but NFQA_VLAN_TCI missing), the function returns immediately without freeing the dequeued entry or its sk_buff. This leaks the nf_queue_entry, its associated sk_buff, and all held references (net_device refcounts, struct net refcount). Repeated triggering exhausts kernel memory. Fix this by dropping the entry via nfqnl_reinject() with NF_DROP verdict on the error path, consistent with other error handling in this file.
A vulnerability exists in the Linux kernel's netfilter component, specifically within the nfnetlink_queue subsystem. This issue leads to a memory leak by failing to properly manage queue entries for packets processed under the PF_BRIDGE protocol. When the nfqa_parse_bridge() function encounters a VLAN attribute error, it does not release the dequeued entry or its associated socket buffer, causing a gradual exhaustion of kernel memory. The leaked entries retain references to net devices and other kernel structures, compounding the memory issue. This vulnerability affects several versions of the Linux kernel.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version of the stable Linux kernel to address this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0b18d1b834ab5a5009be70b530f978d7989e445b | kernel.org | Patch |
| https://git.kernel.org/stable/c/208669df703a25a601f45822b10c413f258bf275 | kernel.org | Patch |
| https://git.kernel.org/stable/c/47b1c5d1b0944aa88299f55a846fabaefc756982 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9853d94b82d303fc4ac37d592a23a154096ecd41 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a907bea273b60d3e604ec4e8e1f6c49954805794 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b38d2b4603fd3dda24eb8b3dd81c18a0930be97b | kernel.org | Patch |
| https://git.kernel.org/stable/c/cf4a4df38d1747e06fc54f9879bd7a6f4178032f | kernel.org | Patch |
| https://git.kernel.org/stable/c/f1ba83755d81c6fc66ac7acd723d238f974091e9 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.7, < 5.10.253 >= 5.11, < 5.15.203 >= 5.16, < 6.1.167 >= 6.2, < 6.6.130 >= 6.7, < 6.12.78 >= 6.13, < 6.18.19 >= 6.19, < 6.19.9 7.0 rc1 7.0 rc2 7.0 rc3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 21, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | New CVE Received | kernel.org |