GHSA-f37v-5r8j-33m9MediumCVSS 5.5

In the Linux kernel, the following vulnerability has been resolved: esp: fix skb leak with...

Published
April 22, 2026
Last Modified
July 14, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

esp: fix skb leak with espintcp and async crypto

When the TX queue for espintcp is full, esp_output_tail_tcp will return an error and not free the skb, because with synchronous crypto, the common xfrm output code will drop the packet for us.

With async crypto (esp_output_done), we need to drop the skb when esp_output_tail_tcp returns an error.

🔗 References (12)