CVE-2026-43457 PUBLISHED

mctp: i2c: fix skb memory leak in receive path

Assigner: Linux
Reserved: 01.05.2026 Published: 08.05.2026 Updated: 08.05.2026

In the Linux kernel, the following vulnerability has been resolved:

mctp: i2c: fix skb memory leak in receive path

When 'midev->allow_rx' is false, the newly allocated skb isn't consumed by netif_rx(), it needs to free the skb directly.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from f5b8abf9fc3dacd7529d363e26fe8230935d65f8 to 0fb2adbdd5c03e8c9ebcdc48afd414b2724c85eb (excl.)
  • affected from f5b8abf9fc3dacd7529d363e26fe8230935d65f8 to d7900a43b0a314a645ca0a2adf45928dbc7001f4 (excl.)
  • affected from f5b8abf9fc3dacd7529d363e26fe8230935d65f8 to 9f81be2ab9d8e4744871bfb3e868ef413413829f (excl.)
  • affected from f5b8abf9fc3dacd7529d363e26fe8230935d65f8 to 1ec54187e1aa40a4cfa2b265e9a311179f24b98d (excl.)
  • affected from f5b8abf9fc3dacd7529d363e26fe8230935d65f8 to 1b1be322342a6b0085bf6ee52235e5ac9834ec25 (excl.)
  • affected from f5b8abf9fc3dacd7529d363e26fe8230935d65f8 to e3f5e0f22cfc2371e7471c9fd5b4da78f9df7c69 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.18 is affected
  • unaffected from 0 to 5.18 (excl.)
  • unaffected from 6.1.167 to 6.1.* (incl.)
  • unaffected from 6.6.130 to 6.6.* (incl.)
  • unaffected from 6.12.78 to 6.12.* (incl.)
  • unaffected from 6.18.19 to 6.18.* (incl.)
  • unaffected from 6.19.9 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References