CVE-2026-74464
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net: openvswitch: fix skb leak on flow key update failure during ct<br />
<br />
ovs_ct_execute() always steals or frees the skb on failure while<br />
ovs_flow_key_update() does not. So, if it fails and we return right<br />
away, the skb ends up leaked.<br />
<br />
Fix that by breaking instead and letting the common error handling<br />
code at the bottom of the loop to free the skb properly.<br />
<br />
This is a very unlikely scenario as it requires the packet to become<br />
unparseable by applying a set of actions on a previously parseable skb,<br />
but should be fixed nevertheless.<br />
<br />
Reported by Sashiko.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/393f3c72600ab6721d732a0ab245bc896c5b28fc
- https://git.kernel.org/stable/c/736e972f3f8a304158345223ac6e816166a467ce
- https://git.kernel.org/stable/c/bc62e843bc48f933da765ce47079fd992e535794
- https://git.kernel.org/stable/c/e0ba8eaef2a0d02a7a485e6a7157e47272b65cea
- https://git.kernel.org/stable/c/e84dfaac50aab45ad8c670da43e3aa1f97bd2a41



