MEDIUM

CVE-2026-53079

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

net_sched: fix skb memory leak in deferred qdisc drops

When the network stack cleans up the deferred list via qdisc_run_end(),
it operates on the root qdisc. If the root qdisc do not implement the
TCQ_F_DEQUEUE_DROPS flag the packets queue to free are never freed and
gets stranded on the child's local to_free list.

Fix this by making qdisc_dequeue_drop() aware of the root qdisc. It
fetches the root qdisc and check for the TCQ_F_DEQUEUE_DROPS flag. If
the flag is present, the packet is appended directly to the root's
to_free list. Otherwise, drop it directly as it was done before the
optimization was implemented.

Summary dbcve.org

Memory leak in Linux kernel's network scheduler (net_sched) where packets queued for deferred dropping are never freed when the root qdisc doesn't implement the TCQ_F_DEQUEUE_DROPS flag, causing them to become stranded on the child's local to_free list.

Mitigation

Apply the kernel patch that makes qdisc_dequeue_drop() aware of the root qdisc and properly handles packets based on the TCQ_F_DEQUEUE_DROPS flag. Update Linux kernel to version containing the fix.

Patch Commit

Weakness (CWE)

CWE-401 Memory Leak

EPSS Score

0.1%
Probability of exploitation in next 30 days
1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE