CVE-2026-23098
In the Linux kernel, the following vulnerability has been resolved: netrom: fix double-free in nr_route_frame() In nr_route_frame(), old_skb is immediately freed without checking if nr_neigh->ax25 pointer is NULL.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: netrom: fix double-free in nr_route_frame() In nr_route_frame(), old_skb is immediately freed without checking if nr_neigh->ax25 pointer is NULL. Therefore, if nr_neigh->ax25 is NULL, the caller function will free old_skb again, causing a double-free bug. Therefore, to prevent this, we need to modify it to check whether nr_neigh->ax25 is NULL before freeing old_skb.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.19% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-415
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/25aab6bfc31017a7e52035b99aef5c2b6bde8ffbPatch
- https://git.kernel.org/stable/c/6e0110ea90313b7c0558a0b77038274a6821caf8Patch
- https://git.kernel.org/stable/c/7c48fdf2d1349bb54815b56fb012b9d577707708Patch
- https://git.kernel.org/stable/c/94d1a8bd08af1f4cc345c5c29f5db1ea72b8bb8cPatch
- https://git.kernel.org/stable/c/9f5fa78d9980fe75a69835521627ab7943cb3d67Patch
- https://git.kernel.org/stable/c/ba1096c315283ee3292765f6aea4cca15816c4f7Patch
- https://git.kernel.org/stable/c/bd8955337e3764f912f49b360e176d8aaecf7016Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.