CVE-2026-22979Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23

Description

In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in skb_segment_list for GRO packets When skb_segment_list() is called during packet forwarding, it handles packets that were aggregated by the GRO engine. Historically, the segmentation logic in skb_segment_list assumes that individual segments are split from a parent SKB and may need to carry their own socket memory accounting. Accordingly, the code transfers truesize from the parent to the newly created

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel5.15.1545.16+7
Debianlinux/linux_kernel< 6.1.162-1+2
CVEListV5linux/linux2eeab8c47c3c0276e0746bc382f405c9a236a5ad0b27828ebd1ed3107d7929c3737adbe862e99e74+7
debiandebian/linux< linux 6.1.162-1 (bookworm)
debiandebian/linux-6.1< linux 6.1.162-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2026-22979: In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in skb_segment_list for GRO packets When skb_segment_list() i2026-01-23
GHSA
GHSA-w4ch-7p82-3m56: In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in skb_segment_list for GRO packets When skb_segment_list()2026-01-23

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: Memory leak in networking due to incorrect GRO packet handling2026-01-23
Debian
CVE-2026-22979: linux - In the Linux kernel, the following vulnerability has been resolved: net: fix me...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-22979 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-22979 — Linux vulnerability | cvebase