SB2026040317 - Memory leak in Linux kernel tls
Published: April 3, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2026-23414)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in tls_decrypt_async_wait() and the async_hold queue when processing pending asynchronous TLS decrypt operations. A local user can trigger a partial failure during message hold handling to cause a denial of service.
This issue results in a memory leak because cloned skbs added to the async_hold queue may not be released in some fallback paths after pending AEAD operations are synchronized. No user interaction is required.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2dcf324855c34e7f934ce978aa19b645a8f3ee71
- https://git.kernel.org/stable/c/6dc11e0bd0a5466bcc76d275c09e5537bd0597dd
- https://git.kernel.org/stable/c/84a8335d8300576f1b377ae24abca1d9f197807f
- https://git.kernel.org/stable/c/9f557c7eae127b44d2e863917dc986a4b6cb1269
- https://git.kernel.org/stable/c/fd8037e1f18ca5336934d0e0e7e1a4fe097e749d