CyberRota
← Ana sayfaya dön

CVE-2026-52981

HIGH · CVSS 7.5 EPSS %0.54

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-24T17:17:08.723 · Çekilme zamanı: 2026-06-30T18:31:47.239276+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-52981
Severity
HIGH
CVSS
7.5
EPSS
%0.54
Linux

Orijinal NVD Açıklaması

In the Linux kernel, the following vulnerability has been resolved: neigh: let neigh_xmit take skb ownership neigh_xmit always releases the skb, except when no neighbour table is found. But even the first added user of neigh_xmit (mpls) relied on neigh_xmit to release the skb (or queue it for tx). sashiko reported: If neigh_xmit() is called with an uninitialized neighbor table (for example, NEIGH_ND_TABLE when IPv6 is disabled), it returns -EAFNOSUPPORT and bypasses its internal out_kfree_skb error path. Because the return value of neigh_xmit() is ignored here, does this leak the SKB? Assume full ownership and remove the last code path that doesn't xmit or free skb.