Junglewise Threat Intelligence

CVE-2026-64526: Linux kernel resource leak in ethtool tsconfig

CVE-2026-64526 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking subsystem specifically affecting how hardware timestamping configurations are handled. In certain error conditions, the system fails to properly release internal resources, which could lead to system instability or resource exhaustion over time. This affects administrators or tools managing network interface settings on Linux-based systems.

Technical details

A resource leak exists in net/ethtool/tsconfig.c within the Linux kernel. The function tsconfig_prepare_data() invokes ethnl_ops_begin() to initialize ethtool netlink operations but fails to call the corresponding ethnl_ops_complete() when encountering an -ENODEV error (specifically when the PHC index is -1). This results in unbalanced operation calls, potentially leaving the netlink interface or associated device locks in an inconsistent state. The issue was introduced in the tsconfig command support and has been resolved by ensuring the completion routine is called during error paths.

Affected products

  • Linux Linux 6.14 to 6.18.35, 7.0.12

Timeline

  • 2026-07-25: disclosed
  • 2026-07-25: advisory

References