CVE-2026-52981

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/06/2026
Last modified:
14/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> neigh: let neigh_xmit take skb ownership<br /> <br /> neigh_xmit always releases the skb, except when no neighbour table is<br /> found. But even the first added user of neigh_xmit (mpls) relied on<br /> neigh_xmit to release the skb (or queue it for tx).<br /> <br /> sashiko reported:<br /> If neigh_xmit() is called with an uninitialized neighbor table (for<br /> example, NEIGH_ND_TABLE when IPv6 is disabled), it returns -EAFNOSUPPORT<br /> and bypasses its internal out_kfree_skb error path. Because the return<br /> value of neigh_xmit() is ignored here, does this leak the SKB?<br /> <br /> Assume full ownership and remove the last code path that doesn&amp;#39;t<br /> xmit or free skb.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.1 (including) 6.1.175 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.141 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.91 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.10 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*