ethtool: rss: fix indir_table and hkey leak on get_rxfh failure

Summary

CVECVE-2026-63999
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-19 16:17:39 UTC
Updated2026-07-19 16:17:39 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure rss_prepare_get() allocates the indirection table and hash key buffer via rss_get_data_alloc(), then calls ops->get_rxfh() to populate them. If get_rxfh() fails, the function returns an error without freeing the allocation.

Risk And Classification

EPSS: 0.001660000 probability, percentile 0.061680000 (date 2026-07-20)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 4f038a6a02d20859a3479293cbf172b0f14cbdd6 33d05c22d6f227c5ae171c46df2f6f8bf48047ea git Not specified
CNA Linux Linux affected 4f038a6a02d20859a3479293cbf172b0f14cbdd6 80d95d92f828cfcace955d673637d944178b435f git Not specified
CNA Linux Linux affected 4f038a6a02d20859a3479293cbf172b0f14cbdd6 266297692f97008ca48bc311775c087c59bd7fe3 git Not specified
CNA Linux Linux affected 81a5174e64ce4fb7b7a2f6499b835c904c9451ee git Not specified
CNA Linux Linux affected ec9faff49a4ea27731de39cb887b7e590e93157b git Not specified
CNA Linux Linux affected c5ed0eaddcbda56079091fc3876b140a6e70a548 git Not specified
CNA Linux Linux affected a065b996052656a65afc51ad82336dc55ae4c72f git Not specified
CNA Linux Linux affected adee9db710a6117b978a25ed4153846b7c56ec9a git Not specified
CNA Linux Linux affected 5eb3fdc4b6281b29e830300c866a36d90442b1f0 git Not specified
CNA Linux Linux affected 5.15.181 5.16 semver Not specified
CNA Linux Linux affected 6.1.135 6.2 semver Not specified
CNA Linux Linux affected 6.6.88 6.7 semver Not specified
CNA Linux Linux affected 6.12.24 6.13 semver Not specified
CNA Linux Linux affected 6.13.12 6.14 semver Not specified
CNA Linux Linux affected 6.14.3 6.15 semver Not specified
CNA Linux Linux affected 6.15 Not specified
CNA Linux Linux unaffected 6.15 semver Not specified
CNA Linux Linux unaffected 6.18.35 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.12 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/33d05c22d6f227c5ae171c46df2f6f8bf48047ea 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/80d95d92f828cfcace955d673637d944178b435f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/266297692f97008ca48bc311775c087c59bd7fe3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report