cbcvebase.
CVE-2026-22979
published 2026-01-23

CVE-2026-22979: In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in skb_segment_list for GRO packets When skb_segment_list() is called…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.3th percentile
In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in skb_segment_list for GRO packets When skb_segment_list() is called during packet forwarding, it handles packets that were aggregated by the GRO engine. Historically, the segmentation logic in skb_segment_list assumes that individual segments are split from a parent SKB and may need to carry their own socket memory accounting. Accordingly, the code transfers truesize from the parent to the newly created segments. Prior to commit ed4cccef64c1 ("gro: fix ownership transfer"), this truesize subtraction in skb_segment_list() was valid because fragments still carry a reference to the original socket. However, commit ed4cccef64c1 ("gro: fix ownership transfer") changed this behavior by ensuring that fraglist entries are explicitly orphaned (skb->sk = NULL) to prevent illegal orphaning later in the stack. This change meant that the entire socket memory charge remained with the head SKB, but the corresponding accounting logic in skb_segment_list() was never updated. As a result, the current code unconditionally adds each fragment's truesize to delta_truesize and subtracts it from the parent SKB. Since the fragments are no longer charged to the socket, this subtraction results in an effective under-count of memory when the head is freed. This causes sk_wmem_alloc to remain non-zero, preventing socket destruction and leading to a persistent memory leak. The leak can be observed via KMEMLEAK when tearing down the networking environment: unreferenced object 0xffff8881e6eb9100 (size 2048): comm "ping", pid 6720, jiffies 4295492526 backtrace: kmem_cache_alloc_noprof+0x5c6/0x800 sk_prot_alloc+0x5b/0x220 sk_alloc+0x35/0xa00 inet6_create.part.0+0x303/0x10d0 __sock_create+0x248/0x640 __sys_socket+0x11b/0x1d0 Since skb_segment_list() is exclusively used for SKB_GSO_FRAGLIST packets constructed by GRO, the truesize adjustment is removed. The call to skb_release_head_state() must be pres

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 2eeab8c47c3c0276e0746bc382f405c9a236a5ad < 0b27828ebd1ed3107d7929c3737adbe862e99e740b27828ebd1ed3107d7929c3737adbe862e99e74
linuxlinux>= 5.15.154 < 5.165.16
linuxlinux>= 6.1.85 < 6.1.1616.1.161
linuxlinux>= 6.6.26 < 6.6.1216.6.121
linuxlinux>= 6.8.5 < 6.96.9
linuxlinux>= ed4cccef64c1d0d5b91e69f7a8a6697c3a865486 < 3264881431e308b9c72cb8a0159d57a56d67dd793264881431e308b9c72cb8a0159d57a56d67dd79
linuxlinux>= ed4cccef64c1d0d5b91e69f7a8a6697c3a865486 < c114a32a2e70b82d447f409f7ffcfa3058f9d5bdc114a32a2e70b82d447f409f7ffcfa3058f9d5bd
linuxlinux>= ed4cccef64c1d0d5b91e69f7a8a6697c3a865486 < 238e03d0466239410b72294b79494e43d4fabe77238e03d0466239410b72294b79494e43d4fabe77
linuxlinux>= fc126c1d51e9552eacd2d717b9ffe9262a8a4cd6 < 88bea149db2057112af3aaf63534b24fab5858ab88bea149db2057112af3aaf63534b24fab5858ab
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.