{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-46102","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-05-13T15:03:33.097Z","datePublished":"2026-05-27T12:59:09.526Z","dateUpdated":"2026-08-05T12:29:38.661Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:29:38.661Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: strparser: fix skb_head leak in strp_abort_strp()\n\nWhen the stream parser is aborted, for example after a message assembly timeout,\nit can still hold a reference to a partially assembled message in\nstrp->skb_head.\n\nThat skb is not released in strp_abort_strp(), which leaks the partially\nassembled message and can be triggered repeatedly to exhaust memory.\n\nFix this by freeing strp->skb_head and resetting the parser state in the\nabort path. Leave strp_stop() unchanged so final cleanup still happens in\nstrp_done() after the work and timer have been synchronized."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The strparser parses data received from a remote TCP peer (espintcp ESP-in-TCP framing, sockmap framed protocols); the leak is driven by a remote peer sending a partial length-prefixed frame that never completes.\nAC:L - The attacker reliably sends an incomplete framed message and simply lets the message-assembly timer expire; this trigger is fully under the attacker's control.\nPR:N - The framing parse (length-prefix read) occurs at the stream layer before any authentication of the payload, so a remote peer needs no privileges on the target to send partial frames and trigger the leak.\nUI:N - No victim interaction is required; the leak is triggered solely by the attacker's network data and the timeout firing.\nS:U - The leaked skb is kernel memory within the same security authority; no security boundary is crossed.\nC:N - The leaked partial-message skb is orphaned, not exposed to the attacker; the bug discloses no information.\nI:N - Nothing is overwritten or modified; the parser is stopped and the dangling pointer is never reused, so there is no integrity impact.\nA:H - Each abort leaks a partial message (up to sk_rcvbuf) and the commit notes it can be triggered repeatedly to exhaust memory, leading to kernel-wide memory exhaustion / OOM denial of service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/strparser/strparser.c"],"versions":[{"version":"43a0c6751a322847cb6fa0ab8cbf77a1d08bfc0a","lessThan":"d6668ce0e78d23eabecef9a6bc4f0f739cb28ad3","status":"affected","versionType":"git"},{"version":"43a0c6751a322847cb6fa0ab8cbf77a1d08bfc0a","lessThan":"a470ed71c906cc8cbad0d74c9942216698911f8b","status":"affected","versionType":"git"},{"version":"43a0c6751a322847cb6fa0ab8cbf77a1d08bfc0a","lessThan":"c2e57695ec9ff9d42f23de70f3805199153d007b","status":"affected","versionType":"git"},{"version":"43a0c6751a322847cb6fa0ab8cbf77a1d08bfc0a","lessThan":"e9ae00490d474757c0f9c65073de83e6bb1e5a00","status":"affected","versionType":"git"},{"version":"43a0c6751a322847cb6fa0ab8cbf77a1d08bfc0a","lessThan":"5327dad2ffe9c1b49881dd6d51ff3c6893847568","status":"affected","versionType":"git"},{"version":"43a0c6751a322847cb6fa0ab8cbf77a1d08bfc0a","lessThan":"19ca9475f18f991735f98a22e735c43e95e6298d","status":"affected","versionType":"git"},{"version":"43a0c6751a322847cb6fa0ab8cbf77a1d08bfc0a","lessThan":"56082f442023db9be1a5a29d4ee361de4017c0b7","status":"affected","versionType":"git"},{"version":"43a0c6751a322847cb6fa0ab8cbf77a1d08bfc0a","lessThan":"fe72340daaf1af588be88056faf98965f39e6032","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/strparser/strparser.c"],"versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","status":"unaffected","versionType":"semver"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.140","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.86","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.27","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.4","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"5.10.258"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"5.15.209"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.1.175"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.6.140"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.12.86"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.18.27"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"7.0.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d6668ce0e78d23eabecef9a6bc4f0f739cb28ad3"},{"url":"https://git.kernel.org/stable/c/a470ed71c906cc8cbad0d74c9942216698911f8b"},{"url":"https://git.kernel.org/stable/c/c2e57695ec9ff9d42f23de70f3805199153d007b"},{"url":"https://git.kernel.org/stable/c/e9ae00490d474757c0f9c65073de83e6bb1e5a00"},{"url":"https://git.kernel.org/stable/c/5327dad2ffe9c1b49881dd6d51ff3c6893847568"},{"url":"https://git.kernel.org/stable/c/19ca9475f18f991735f98a22e735c43e95e6298d"},{"url":"https://git.kernel.org/stable/c/56082f442023db9be1a5a29d4ee361de4017c0b7"},{"url":"https://git.kernel.org/stable/c/fe72340daaf1af588be88056faf98965f39e6032"}],"title":"net: strparser: fix skb_head leak in strp_abort_strp()","x_generator":{"engine":"bippy-1.2.0"}}}}