← All Advisories

CVE-2026-97597

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97597

Key Details

CVECVE-2026-97597
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ipv6: flowlabel: cap duplicate leases per socket

ipv6_flowlabel_get() allocates an ipv6_fl_socklist entry for every

successful GET. The recheck path for a compatible existing flowlabel

links another lease without applying any lease admission check. Repeated

GET requests for one shareable label can therefore grow a socket's lease

list without bound.

Reject a new unprivileged lease once the socket already holds

FL_MAX_PER_SOCK leases. Check this on the shared recheck path so reuse

of a globally interned label, including the fl_intern() collision path,

is covered as well. New-label admission remains under the existing

mem_check() policy.

Use capable(CAP_NET_ADMIN) rather than ns_capable(), matching

mem_check(). An unprivileged user must not bypass the cap by creating a

user namespace and a netns where they have CAP_NET_ADMIN, which would

still consume host memory.

Check the capability only when the socket reaches the limit, so

successful unprivileged GET requests below the cap do not generate a

capability audit. Do the admission check before updating linger and

expires so a rejected GET does not refresh the shared label, matching

the existing socket-list allocation failure path. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97597
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97597