PT-2026-28332 · Linux · Linux Kernel

Published

2026-01-01

·

Updated

2026-04-20

·

CVE-2026-23399

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a memory leak within the nf tables module, specifically in the nft dynset component. This issue occurs when cloning stateful expressions. If the allocation of the second stateful expression fails during the cloning process via GFP ATOMIC, the first stateful expression remains allocated but unreferenced, leading to a memory leak. The affected functions include pcpu alloc noprof, nft counter clone, nft expr clone, nft dynset new, nft rhash update, nft dynset eval, nft do chain, nft do chain ipv4, and nf hook slow.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Weakness Enumeration

Related Identifiers

CVE-2026-23399
ECHO-7B1B-5BD3-02E3
OESA-2026-1862
OESA-2026-1863
OESA-2026-1864
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:2217-1

Affected Products

Linux Kernel