CVE-2026-23072Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 4

Description

In the Linux kernel, the following vulnerability has been resolved: l2tp: Fix memleak in l2tp_udp_encap_recv(). syzbot reported memleak of struct l2tp_session, l2tp_tunnel, sock, etc. [0] The cited commit moved down the validation of the protocol version in l2tp_udp_encap_recv(). The new place requires an extra error handling to avoid the memleak. Let's call l2tp_session_put() there. [0]: BUG: memory leak unreferenced object 0xffff88810a290200 (size 512): comm "syz.0.17", pid 6086, jiffies

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel6.106.12.68+2
Debianlinux/linux_kernel< 6.12.69-1+1
CVEListV5linux/linux364798056f518b0bf2f17cd9eaf0dd4e856d73935cd158a88eef34e7b100cd9b963873d3b4e41b35+3

Patches

🔴Vulnerability Details

3
CVEList
l2tp: Fix memleak in l2tp_udp_encap_recv().2026-02-04
GHSA
GHSA-fm5m-5cr7-5q35: In the Linux kernel, the following vulnerability has been resolved: l2tp: Fix memleak in l2tp_udp_encap_recv()2026-02-04
OSV
CVE-2026-23072: In the Linux kernel, the following vulnerability has been resolved: l2tp: Fix memleak in l2tp_udp_encap_recv()2026-02-04

📋Vendor Advisories

2
Red Hat
kernel: l2tp: Fix memleak in l2tp_udp_encap_recv()2026-02-04
Debian
CVE-2026-23072: linux - In the Linux kernel, the following vulnerability has been resolved: l2tp: Fix m...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23072 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23072 — Linux vulnerability | cvebase