Allocation of Resources Without Limits or Throttling in Linux kernel - CVE-2026-97939
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to missing memory accounting in IPv4 and IPv6 multicast routing table allocations when creating multicast routing tables with MRT_TABLE or MRT6_TABLE. A local privileged user can create many multicast routing tables to cause a denial of service.
Exploitation requires netadmin privileges in a user and network namespace.