net: openvswitch: fix possible kfree_skb of ERR_PTR

Summary

CVECVE-2026-53227
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-06-25 09:16:40 UTC
Updated2026-06-25 09:16:40 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix possible kfree_skb of ERR_PTR After the patch in the "Fixes" tag, the allocation of the "reply" skb can happen either before or after locking the ovs_mutex. However, error cleanups still follow the classical reversed order, assuming "reply" is allocated before locking: it is freed after unlocking. If "reply" allocation happens after locking the mutex and it fails, "reply" is left with an ERR_PTR, and execution jumps to the correspondent cleanup stage which will try to free an invalid pointer. Fix this by setting the pointer to NULL after having saved its error value.

Risk And Classification

EPSS: 0.001980000 probability, percentile 0.097750000 (date 2026-06-25)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 893f139b9a6c00c097b9082a90f3041cfb3a0d20 e248fb2e680deb2bd37bac551b72638fe4938a76 git Not specified
CNA Linux Linux affected 893f139b9a6c00c097b9082a90f3041cfb3a0d20 0bb5b2dc1b90aa7dd1473fc8c4d813a29255ff8d git Not specified
CNA Linux Linux affected 893f139b9a6c00c097b9082a90f3041cfb3a0d20 971b1b37774f13acc5add0a2843f8598446b8598 git Not specified
CNA Linux Linux affected 893f139b9a6c00c097b9082a90f3041cfb3a0d20 25fdf53698535fe8790237f5a8a9626791429785 git Not specified
CNA Linux Linux affected 893f139b9a6c00c097b9082a90f3041cfb3a0d20 e3d509a1b71396e1452060dbf84a805fd1c3c549 git Not specified
CNA Linux Linux affected 893f139b9a6c00c097b9082a90f3041cfb3a0d20 ecc55aad3390129a87106841f4b68bf3d70c9264 git Not specified
CNA Linux Linux affected 893f139b9a6c00c097b9082a90f3041cfb3a0d20 895d1dd9057cde1687fa0f4286d47ceed0b82997 git Not specified
CNA Linux Linux affected 893f139b9a6c00c097b9082a90f3041cfb3a0d20 ee30dd2909d8b98619f4341c70ec8dc8e155ab02 git Not specified
CNA Linux Linux affected 3.16 Not specified
CNA Linux Linux unaffected 3.16 semver Not specified
CNA Linux Linux unaffected 5.10.259 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.210 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.176 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.143 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.94 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.36 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.13 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/e248fb2e680deb2bd37bac551b72638fe4938a76 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/971b1b37774f13acc5add0a2843f8598446b8598 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e3d509a1b71396e1452060dbf84a805fd1c3c549 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ee30dd2909d8b98619f4341c70ec8dc8e155ab02 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/25fdf53698535fe8790237f5a8a9626791429785 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/0bb5b2dc1b90aa7dd1473fc8c4d813a29255ff8d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/895d1dd9057cde1687fa0f4286d47ceed0b82997 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ecc55aad3390129a87106841f4b68bf3d70c9264 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report