Resource exhaustion in Linux kernel - CVE-2026-97598
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in fib_empty_table() in IPv4 FIB rules when adding an IPv4 rule with automatic table assignment. A local user can populate table IDs and add a table-0 rule to cause a denial of service.
Only the IPv4 automatic table-assignment path is affected.