CVE-2026-63872
Received Received - Intake

Page Frag Reference Leak in Linux Kernel ESP

Vulnerability report for CVE-2026-63872, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-19

Last updated on: 2026-07-19

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: esp: fix page frag reference leak on skb_to_sgvec failure In esp_output_tail(), when esp->inplace is false, the old skb page frags are replaced with a new page from the xfrm page_frag cache. The source scatterlist (sg) is built from the old frags before the replacement, and esp_ssg_unref() is responsible for releasing the old page references after the crypto operation completes. However, if the second skb_to_sgvec() call (which builds the destination scatterlist from the new page) fails, the code jumps to error_free which only calls kfree(tmp). The old page frag references captured in the source scatterlist are never released: 1. sg[] is built from old frags via skb_to_sgvec() (no extra get_page) 2. nr_frags is set to 1 and frag[0] is replaced with the new page 3. Second skb_to_sgvec() fails -> goto error_free 4. kfree(tmp) frees the sg[] memory but old frags are not unref'd 5. kfree_skb() only releases frag[0] (the new page), not the old ones Fix this by adding a bool parameter to esp_ssg_unref() that, when true, unconditionally unrefs the source scatterlist frags without checking req->src and req->dst, since those fields are not yet initialized by aead_request_set_crypt() at the point of the error. Existing callers pass false to preserve the original behavior. The same issue exists in both esp4 and esp6 as the code is identical.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-19
Last Modified
2026-07-19
Generated
2026-07-20
AI Q&A
2026-07-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel to 416baaa9-dc9f-4396-8d5f-8c081fb06d67 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability where a page fragment reference leak occurs in the ESP (Encapsulating Security Payload) module. When processing network packets, the code fails to properly release old page references if an error happens during scatterlist creation, leading to a memory leak.

Detection Guidance

This vulnerability is specific to the Linux kernel's ESP (Encapsulating Security Payload) implementation and may not have direct detection commands. Monitor kernel logs for errors related to ESP operations or page frag leaks. Check for crashes or memory leaks in networking-related processes.

Impact Analysis

The vulnerability could cause memory leaks in systems using ESP for network encryption, potentially leading to resource exhaustion. This may result in system instability or crashes under heavy network load.

Compliance Impact

This vulnerability is a memory leak in the Linux kernel's ESP (Encapsulating Security Payload) implementation. It does not directly affect data privacy or security controls that GDPR or HIPAA typically address. Compliance with these standards depends on proper data handling, encryption, and access controls, which are not directly impacted by this memory management issue.

Mitigation Strategies

Apply the latest kernel patches from your Linux distribution to resolve the issue. If patching is not immediately possible, consider disabling ESP (Encapsulating Security Payload) in your IPsec configuration as a temporary workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63872. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart