Back to overview

CVE-2026-52981

Description
In the Linux kernel, the following vulnerability has been resolved: neigh: let neigh_xmit take skb ownership neigh_xmit always releases the skb, except when no neighbour table is found. But even the first added user of neigh_xmit (mpls) relied on neigh_xmit to release the skb (or queue it for tx). sashiko reported: If neigh_xmit() is called with an uninitialized neighbor table (for example, NEIGH_ND_TABLE when IPv6 is disabled), it returns -EAFNOSUPPORT and bypasses its internal out_kfree_skb error path. Because the return value of neigh_xmit() is ignored here, does this leak the SKB? Assume full ownership and remove the last code path that doesn't xmit or free skb.

Metadata

CVE ID
CVE-2026-52981
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-24 16:28 UTC
Last updated
2026-06-24 16:28 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 4fd3d7d9e868ffbdb0e7a67c5c8e9dfdcd846a62 < 8a89054a1ec0767aec25ed2bbac933da6ba3cf5a, 4fd3d7d9e868ffbdb0e7a67c5c8e9dfdcd846a62 < 9247d59ca15bf60a57dca08103f055d8a4340877, 4fd3d7d9e868ffbdb0e7a67c5c8e9dfdcd846a62 < 0084712e0bee204b284510cdb63182fd5a30c2b7, 4fd3d7d9e868ffbdb0e7a67c5c8e9dfdcd846a62 < 63063ba60d2dc334e34f1e3f9271d7f3f6f30307 …
Linux Linux 4.1, 0 < 4.1, 6.1.175 ≤ 6.1.*, 6.6.141 ≤ 6.6.* …
Back to overview