Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-63835

 

Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-63835

Published: July 21, 2026


Vulnerability identifier: #VU138826
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-63835
CWE-ID: CWE-772
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in batadv_v_ogm_queue_on_if() and the OGM aggregation queue handling when processing OGM aggregation on a disabled hard interface. A local user can trigger interface disablement while causing new skbs to be queued to the aggregation list to cause a denial of service.

The issue can lead to skbs being queued after the worker has been disabled, and these queued skbs are never freed or consumed.


Affected software

Linux kernel

How to mitigate CVE-2026-63835

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins