Executive brief
A memory leak vulnerability was identified in the Linux kernel's networking subsystem, specifically within the ethtool RSS (Receive Side Scaling) configuration component. When the system attempts to retrieve certain network interface settings and encounters an error, it fails to release previously allocated memory. Over time, repeated occurrences of this error could lead to excessive memory consumption, potentially impacting system performance or stability.
Technical details
A memory leak exists in net/ethtool/rss.c within the Linux kernel. The function rss_prepare_get() allocates memory for the indirection table and hash key buffer using rss_get_data_alloc(). It then invokes the driver-specific ops->get_rxfh() callback to populate these buffers. If the callback returns an error, the function exits without calling rss_get_data_free(), resulting in a leak of the allocated memory. This is a local vulnerability that can be triggered during ethtool RSS query operations. The issue has been resolved by ensuring rss_get_data_free() is called in the error path.
Affected products
- Linux Linux Kernel 5.15.181, 6.1.135, 6.6.88, 6.12.24, 6.13.12, 6.14.3, 6.15
Timeline
- 2026-05-22: disclosed: Initial patch submitted by Jakub Kicinski
- 2026-06-09: patched: Patch committed to stable trees
- 2026-07-19: advisory: CVE published by NVD