AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72401

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's BPF (Berkeley Packet Filter) subsystem, where a failure in memory allocation can lead to a leak of sensitive data stored in `insn_aux_data`. This issue can potentially expose sensitive information, making it critical for organizations using Linux systems with BPF functionality to prioritize remediation. System administrators and security teams should assess their environments for this vulnerability to prevent potential data leaks.

CVE
CVE-2026-72401
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix insn_aux_data leak on verifier err_free_env path When bpf_check() allocates env->insn_aux_data successfully but later fails to allocate env->succ, it jumps directly to err_free_env. The existing vfree(env->insn_aux_data) sits before the err_free_env label, so that direct jump bypasses it and leaks insn_aux_data. Move vfree(env->insn_aux_data) into err_free_env so all early and late exit paths release it consistently.