Memory leak in Linux kernel - CVE-2026-100076

 

Memory leak in Linux kernel - CVE-2026-100076

Published: September 28, 2026


Vulnerability identifier: #VU152273
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-100076
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to failure to release management transmit frame and buffer resources in the rtl8723bs management frame transmission paths when handling management frame transmission error conditions. A local user can repeatedly trigger affected error paths to exhaust the management transmit pools and prevent the interface from sending beacons or probe and association responses.


Affected software

Linux kernel

How to mitigate CVE-2026-100076

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins