CVE-2026-23095Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 89.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4
Latest updateApr 17

Description

In the Linux kernel, the following vulnerability has been resolved: gue: Fix skb memleak with inner IP protocol 0. syzbot reported skb memleak below. [0] The repro generated a GUE packet with its inner protocol 0. gue_udp_recv() returns -guehdr->proto_ctype for "resubmit" in ip_protocol_deliver_rcu(), but this only works with non-zero protocol number. Let's drop such packets. Note that 0 is a valid number (IPv6 Hop-by-Hop Option). I think it is not practical to encap HOPOPT in GUE, so onc

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages12 packages

NVDlinux/linux_kernel3.185.10.249+6
Debianlinux/linux_kernel< 5.10.249-1+3
CVEListV5linux/linux37dd0247797b168ad1cc7f5dbec825a1ee66535b886f186328b718400dbf79e1bc8cbcbd710ab766+7
debiandebian/linux< linux 6.1.162-1 (bookworm)
debiandebian/linux-6.1< linux 6.1.162-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fg3v-8p2h-99jg: In the Linux kernel, the following vulnerability has been resolved: gue: Fix skb memleak with inner IP protocol 02026-02-04
OSV
CVE-2026-23095: In the Linux kernel, the following vulnerability has been resolved: gue: Fix skb memleak with inner IP protocol 02026-02-04

📋Vendor Advisories

8
Ubuntu
Linux kernel (HWE) vulnerabilities2026-04-17
Ubuntu
Linux kernel (NVIDIA) vulnerabilities2026-04-17
Ubuntu
Linux kernel (FIPS) vulnerabilities2026-04-17
Ubuntu
Linux kernel (Real-time) vulnerabilities2026-04-17
Ubuntu
Linux kernel vulnerabilities2026-04-16

🕵️Threat Intelligence

1
Wiz
CVE-2026-23095 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23095 — Linux vulnerability | cvebase