CVE-2026-43457
Description
A flaw was found in the Linux kernel's Management Component Transport Protocol (MCTP) over I2C receive path. When the midev->allow_rx flag is false, a newly allocated network buffer (skb) is not properly freed. This memory leak can lead to a gradual exhaustion of system memory, potentially allowing a local attacker to cause a Denial of Service (DoS).
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (Other); DoS: Resource Consumption (Memory); DoS: Resource Consumption (CPU)
An attacker that can influence the allocation of resources that are not properly released could deplete the available resource pool and prevent all other processes from accessing the same type of resource. Frequently-affected resources include memory, CPU, disk space, power or battery, etc.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.