Memory leak in Linux kernel - CVE-2026-89565
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a resource leak in ipip_tunnel_rcv() when processing packets in collect_md mode after metadata_dst allocation fails. A local user can trigger packet processing under these conditions to cause a denial of service.
The issue can be triggered through an ipip or mplsip tunnel configured in collect_md mode.