Executive brief
A vulnerability in the Linux kernel's networking component can cause a persistent memory leak during certain network traffic operations. This occurs when the system processes aggregated network packets, leading to incorrect memory accounting that prevents the system from reclaiming resources. Over time, this can exhaust available system memory, potentially leading to a system crash or service outage.
Technical details
A memory leak exists in the Linux kernel's networking stack within the skb_segment_list() function. The root cause is an incorrect memory accounting logic where the 'truesize' of packet fragments is subtracted from the parent socket buffer (SKB) even though the fragments no longer carry socket ownership. This results in an under-count of memory when the head SKB is freed, causing the socket memory allocation counter (sk_wmem_alloc) to remain non-zero. This prevents the destruction of the associated socket and leads to a persistent leak of kernel memory. The issue is triggered during packet forwarding of SKB_GSO_FRAGLIST packets aggregated by the GRO engine. Patches have been released for various stable kernel branches.
Affected products
- Linux Linux Kernel versions prior to 6.13, 6.12.10, 6.11.11, 6.6.72, 6.1.125
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later
Timeline
- 2026-01-04: other: Patch submitted by developer
- 2026-01-23: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0b27828ebd1ed3107d7929c3737adbe862e99e74
- https://git.kernel.org/stable/c/238e03d0466239410b72294b79494e43d4fabe77
- https://git.kernel.org/stable/c/3264881431e308b9c72cb8a0159d57a56d67dd79
- https://git.kernel.org/stable/c/88bea149db2057112af3aaf63534b24fab5858ab
- https://git.kernel.org/stable/c/c114a32a2e70b82d447f409f7ffcfa3058f9d5bd
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html