CVE-2026-63999: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure rss_prepare_get() allocates the indirection table and hash key buffer via rss_get_data_alloc(), then calls ops->get_rxfh() to populate them. If get_rxfh() fails, the function returns an error without freeing the allocation.

Affected products

  • Linux Linux Kernel: from 5.15.181, before 5.16 (fixed in 5.16); from 6.1.135, before 6.2 (fixed in 6.2); from 6.6.88, before 6.7 (fixed in 6.7); from 6.12.24, before 6.13 (fixed in 6.13); from 6.13.12, before 6.14 (fixed in 6.14); from 6.14.3, before 6.15 (fixed in 6.15); …

Published 2026-07-19. Last modified 2026-10-08.