A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.82/6.18.23/6.19.13. The impacted element is the function xfrm_pol_hold_rcu of the file net/xfrm/xfrm_policy.c. The manipulation leads to memory leak.

This vulnerability is listed as CVE-2026-43090. The attack must be carried out from within the local network. There is no available exploit.

It is advisable to upgrade the affected component.