CVE-2026-23024Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 94.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31

Description

In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leak of flow steer list on rmmod The flow steering list maintains entries that are added and removed as ethtool creates and deletes flow steering rules. Module removal with active entries causes memory leak as the list is not properly cleaned up. Prevent this by iterating through the remaining entries in the list and freeing the associated memory during module removal. Add a spinlock (flow_steer_list_lock) to

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Linuxlinux/linux_kernel6.17.06.18.6
NVDlinux/linux_kernel6.17.16.18.6+2
Debianlinux/linux_kernel< 6.18.8-1
CVEListV5linux/linuxada3e24b84a097b27a823f1ad98e5b2e8c9796891aedff70a5e97628eaaf17b169774cb6a45a1dc5+2
debiandebian/linux< linux 6.18.8-1 (forky)

Patches

🔴Vulnerability Details

3
OSV
idpf: fix memory leak of flow steer list on rmmod2026-01-31
OSV
CVE-2026-23024: In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leak of flow steer list on rmmod The flow steering list maintains2026-01-31
GHSA
GHSA-jv8h-wwpc-ccw4: In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leak of flow steer list on rmmod The flow steering list maintai2026-01-31

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel (idpf): Memory leak leading to denial of service via improper cleanup during module removal2026-01-31
Debian
CVE-2026-23024: linux - In the Linux kernel, the following vulnerability has been resolved: idpf: fix m...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23024 Impact, Exploitability, and Mitigation Steps | Wiz