Junglewise Threat Intelligence

CVE-2026-43102: Linux Kernel Airoha Ethernet driver memory leak in airoha_qdma_rx_process

CVE-2026-43102 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak vulnerability exists in the Linux kernel's Airoha Ethernet driver. This issue occurs when the system fails to properly release memory during network packet processing errors, potentially leading to a gradual depletion of system resources. If exploited, this could result in a denial-of-service condition, impacting the stability and availability of the affected system.

Technical details

A memory leak exists in the airoha_qdma_rx_process() function within the Airoha Ethernet driver (drivers/net/ethernet/airoha/airoha_eth.c). The vulnerability is triggered when an error occurs while processing non-linear skb fragments, such as an incorrect payload length reported by the NIC or exhaustion of available fragments. In these error paths, page_pool fragments are not correctly linked to the skb or returned to the pool, causing the memory to remain allocated indefinitely. The fix involves ensuring page_pool_put_full_page is always called during the error path to properly recycle memory. Patches have been released for various stable kernel branches including 6.18.24 and 6.19.14.

Affected products

  • Linux Linux Kernel 6.15.1 to 6.18.24, 6.19 to 6.19.14, 7.0-rc1 to 7.0-rc7

Timeline

  • 2026-04-02: other: Patch submitted by developer
  • 2026-05-06: disclosed: CVE published
  • 2026-05-06: advisory

References

Related threats