CVE-2026-68379

medium

Description

In the Linux kernel, the following vulnerability has been resolved: tcp: fix TIME_WAIT socket reference leak on PSP policy failure Release the TIME_WAIT socket reference and jump to discard_it upon PSP policy failure in both IPv4 and IPv6 receive paths. This prevents a memory leak of tcp_tw_bucket structures.

References

https://git.kernel.org/stable/c/e666af5dcc905ba694745963174d232deb478c55

https://git.kernel.org/stable/c/374742a961becbbfc7fbfd1382d978a05e492741

https://git.kernel.org/stable/c/2c1931a81122c3cdc4c89448fe0442c69e21c0d5

Details

Source: Mitre, NVD

Published: 2026-08-10

Updated: 2026-08-10

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium