Memory leak in Linux kernel - CVE-2026-100071

 

Memory leak in Linux kernel - CVE-2026-100071

Published: September 28, 2026


Vulnerability identifier: #VU152276
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-100071
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource cleanup in HSR device setup error handling when receiving frames after an RX handler has been registered and device setup subsequently fails. A remote attacker can send frames during HSR device setup to cause a denial of service.


Affected software

Linux kernel

How to mitigate CVE-2026-100071

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins