HIGHCVE-2026-43481Published Modified CNA Linux
CVE-2026-43481: net-shapers: don't free reply skb after genlmsg_reply()
In the Linux kernel, the following vulnerability has been resolved: net-shapers: don't free reply skb after genlmsg_reply() genlmsg_reply() hands the reply skb to netlink, and netlink_unicast() consumes it on all return paths, whether the skb is queued successfully or freed on an error path. net_shaper_nl_get_doit() and net_shaper_nl_cap_get_doit() currently jump to free_msg after genlmsg_reply() fails and call nlmsg_free(msg), which can hit the same skb twice. Return the genlmsg_reply() error directly and keep free_msg only for pre-reply failures.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- 0
- Affected Products
- 2
Fix available
057885276cc16a2e2b76282c808a4e84cbecb3aae6.18.196.19.97.083f7b54242d0abbfce35a55c01322f50962ed3ee8738dcc844fff7d0157ee775230e95df3b1884d7
Affected packages
- Linux / Linux< 8738dcc844fff7d0157ee775230e95df3b1884d7 (from 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb) · < 83f7b54242d0abbfce35a55c01322f50962ed3ee (from 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb) · < 57885276cc16a2e2b76282c808a4e84cbecb3aae (from 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb)
- Linux / Linux6.13Fixed in 0, 6.18.19, 6.19.9, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H