Memory leak in Linux kernel - CVE-2026-97959
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a memory leak.
The vulnerability exists due to a failure to free an emptied route4 bucket in net/sched/cls_route.c route4_change when moving an existing route filter to a different top-level bucket and deleting it. A local user can move an existing route filter to a different top-level bucket and then delete it to cause a memory leak.
The issue requires CONFIG_NET_CLS_ROUTE4, CONFIG_NET_SCH_INGRESS, and CONFIG_NET_CLS_ACT to be enabled.