PT-2026-27704 · Linux · Linux Kernel

CVE-2026-23339

·

Publicado

2026-01-01

·

Atualizado

2026-06-30

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The nci transceive() function in the Linux kernel does not free memory allocated to skb (socket buffer) in certain error scenarios, specifically when encountering -EPROTO, -EINVAL, or -EBUSY errors. This can lead to memory leaks. The issue is related to clearing NCI DATA EXCHANGE and was observed during the nci/nci dev selftest in NIPA, detected by kmemleak. The function nci transceive() takes ownership of the skb passed by the caller, but fails to release it under these error conditions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23339
ECHO-196B-CA17-BE07
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1

Produtos afetados

Linux Kernel