CVE-2026-53227
In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix possible kfree_skb of ERR_PTR After the patch in the "Fixes" tag, the allocation of the "reply" skb can happen either before or after locking the ovs_mutex.
Does this matter?
Lower severity and a low EPSS score (0.13%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix possible kfree_skb of ERR_PTR After the patch in the "Fixes" tag, the allocation of the "reply" skb can happen either before or after locking the ovs_mutex. However, error cleanups still follow the classical reversed order, assuming "reply" is allocated before locking: it is freed after unlocking. If "reply" allocation happens after locking the mutex and it fails, "reply" is left with an ERR_PTR, and execution jumps to the correspondent cleanup stage which will try to free an invalid pointer. Fix this by setting the pointer to NULL after having saved its error value.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.13% probability · 3th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0bb5b2dc1b90aa7dd1473fc8c4d813a29255ff8dPatch
- https://git.kernel.org/stable/c/25fdf53698535fe8790237f5a8a9626791429785Patch
- https://git.kernel.org/stable/c/895d1dd9057cde1687fa0f4286d47ceed0b82997Patch
- https://git.kernel.org/stable/c/971b1b37774f13acc5add0a2843f8598446b8598Patch
- https://git.kernel.org/stable/c/e248fb2e680deb2bd37bac551b72638fe4938a76Patch
- https://git.kernel.org/stable/c/e3d509a1b71396e1452060dbf84a805fd1c3c549Patch
- https://git.kernel.org/stable/c/ecc55aad3390129a87106841f4b68bf3d70c9264Patch
- https://git.kernel.org/stable/c/ee30dd2909d8b98619f4341c70ec8dc8e155ab02Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.