#VU124858 Memory leak in Linux kernel - CVE-2026-23414
Published: April 3, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in tls_decrypt_async_wait() and the async_hold queue when processing pending asynchronous TLS decrypt operations. A local user can trigger a partial failure during message hold handling to cause a denial of service.
This issue results in a memory leak because cloned skbs added to the async_hold queue may not be released in some fallback paths after pending AEAD operations are synchronized. No user interaction is required.
Remediation
External links
- https://git.kernel.org/stable/c/2dcf324855c34e7f934ce978aa19b645a8f3ee71
- https://git.kernel.org/stable/c/6dc11e0bd0a5466bcc76d275c09e5537bd0597dd
- https://git.kernel.org/stable/c/84a8335d8300576f1b377ae24abca1d9f197807f
- https://git.kernel.org/stable/c/9f557c7eae127b44d2e863917dc986a4b6cb1269
- https://git.kernel.org/stable/c/fd8037e1f18ca5336934d0e0e7e1a4fe097e749d