CVE Database
/

CVE-2026-43451

Back to search

CVE-2026-43451

Published: May 8, 2026

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path nfqnl_recv_verdict() calls find_dequeue_entry() to remove the queue entry from the queue data structures, taking ownership of the entry. For PF_BRIDGE packets, it then calls nfqa_parse_bridge() to parse VLAN attributes. If nfqa_parse_bridge() returns an error (e.g. NFQA_VLAN present but NFQA_VLAN_TCI missing), the function returns immediately without freeing the dequeued entry or its sk_buff. This leaks the nf_queue_entry, its associated sk_buff, and all held references (net_device refcounts, struct net refcount). Repeated triggering exhausts kernel memory. Fix this by dropping the entry via nfqnl_reinject() with NF_DROP verdict on the error path, consistent with other error handling in this file.

VendorProductVersions

Linux

Linux

affected
8d45ff22f1b43249f0cf1baafe0262ca10d1666e - < a907bea273b60d3e604ec4e8e1f6c49954805794
affected
8d45ff22f1b43249f0cf1baafe0262ca10d1666e - < 0b18d1b834ab5a5009be70b530f978d7989e445b
affected
8d45ff22f1b43249f0cf1baafe0262ca10d1666e - < b38d2b4603fd3dda24eb8b3dd81c18a0930be97b
affected
8d45ff22f1b43249f0cf1baafe0262ca10d1666e - < 47b1c5d1b0944aa88299f55a846fabaefc756982
affected
8d45ff22f1b43249f0cf1baafe0262ca10d1666e - < cf4a4df38d1747e06fc54f9879bd7a6f4178032f

+3 more versions

Linux

Linux

affected
4.7
unaffected
0 - < 4.7
unaffected
5.10.253 - <= 5.10.*
unaffected
5.15.203 - <= 5.15.*
unaffected
6.1.167 - <= 6.1.*

+5 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now