CVE-2026-43481

Source
https://cve.org/CVERecord?id=CVE-2026-43481
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43481.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-43481
Downstream
Published
2026-05-13T15:08:29.116Z
Modified
2026-07-15T01:49:22.537084263Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net-shapers: don't free reply skb after genlmsg_reply()
Details

In the Linux kernel, the following vulnerability has been resolved:

net-shapers: don't free reply skb after genlmsg_reply()

genlmsgreply() hands the reply skb to netlink, and netlinkunicast() consumes it on all return paths, whether the skb is queued successfully or freed on an error path.

netshapernlgetdoit() and netshapernlcapgetdoit() currently jump to freemsg after genlmsgreply() fails and call nlmsgfree(msg), which can hit the same skb twice.

Return the genlmsgreply() error directly and keep freemsg only for pre-reply failures.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43481.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4b623f9f0f59652ea71fcb27d60b4c3b65126dbb
Fixed
8738dcc844fff7d0157ee775230e95df3b1884d7
Fixed
83f7b54242d0abbfce35a55c01322f50962ed3ee
Fixed
57885276cc16a2e2b76282c808a4e84cbecb3aae

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43481.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.19
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43481.json"