---
id: CVE-2026-31658
title: 'net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()

  When dma_map_single() fails in tse_start_xmit(), the function returns
  NETDEV_TX_OK without freei…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a <
    ae2cd46f57f422b51aedd406ff5d75cbff401d5d
  - >-
    Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a <
    cb1d318702fdf643061350d164250198df4116f2
  - >-
    Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a <
    d5ec406f0543bd6cdfd563b08015fdec8c4d5712
  - >-
    Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a <
    2eb9d67704ca8f1101f7435b85f113ede471f9f2
  - >-
    Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a <
    9f3ec44aeb58501d11834048d5d0dbaeacb6d4e7
  - >-
    Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a <
    60f462cd2716d86bd2174f9d5e035c9278f30480
  - >-
    Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a <
    3aca300e88afe56afb000cdc4c65383014fb17f9
  - >-
    Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a <
    6dede3967619b5944003227a5d09fdc21ed57d10
  - Linux 3.15
published: '2026-04-24'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:47:54.322Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-31658'
references:
  - url: 'https://git.kernel.org/stable/c/ae2cd46f57f422b51aedd406ff5d75cbff401d5d'
  - url: 'https://git.kernel.org/stable/c/cb1d318702fdf643061350d164250198df4116f2'
  - url: 'https://git.kernel.org/stable/c/d5ec406f0543bd6cdfd563b08015fdec8c4d5712'
  - url: 'https://git.kernel.org/stable/c/2eb9d67704ca8f1101f7435b85f113ede471f9f2'
  - url: 'https://git.kernel.org/stable/c/9f3ec44aeb58501d11834048d5d0dbaeacb6d4e7'
  - url: 'https://git.kernel.org/stable/c/60f462cd2716d86bd2174f9d5e035c9278f30480'
  - url: 'https://git.kernel.org/stable/c/3aca300e88afe56afb000cdc4c65383014fb17f9'
  - url: 'https://git.kernel.org/stable/c/6dede3967619b5944003227a5d09fdc21ed57d10'
tags:
  - cve.org
epss: 0.00171
epssPercentile: 0.05678
ingestedAt: '2026-09-08T15:33:26.990Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()

When dma_map_single() fails in tse_start_xmit(), the function returns
NETDEV_TX_OK without freeing the skb. Since NETDEV_TX_OK tells the
stack the packet was consumed, the skb is never freed, leaking memory
on every DMA mapping failure.

Add dev_kfree_skb_any() before returning to properly free the skb.

## Affected

- `Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a < ae2cd46f57f422b51aedd406ff5d75cbff401d5d`
- `Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a < cb1d318702fdf643061350d164250198df4116f2`
- `Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a < d5ec406f0543bd6cdfd563b08015fdec8c4d5712`
- `Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a < 2eb9d67704ca8f1101f7435b85f113ede471f9f2`
- `Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a < 9f3ec44aeb58501d11834048d5d0dbaeacb6d4e7`
- `Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a < 60f462cd2716d86bd2174f9d5e035c9278f30480`
- `Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a < 3aca300e88afe56afb000cdc4c65383014fb17f9`
- `Linux >= bbd2190ce96d8fce031f0526c1f970b68adc9d1a < 6dede3967619b5944003227a5d09fdc21ed57d10`
- `Linux 3.15`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
