* CVE-2026-72017: net: macb: drop in-flight Tx SKBs on close
@ 2026-08-15 6:01 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-15 6:01 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
net: macb: drop in-flight Tx SKBs on close
The MACB driver has since forever leaked the outgoing SKBs that
have not yet been marked as completed. They live in queue->tx_skb
which gets freed without remorse nor checking.
macb_free_consistent() gets called in a few codepaths, but only close will
trigger the added expressions. In macb_open() and macb_alloc_consistent()
failure cases, queues' tx_skb just got allocated and are empty.
The Linux kernel CVE team has assigned CVE-2026-72017 to this issue.
Affected and fixed versions
===========================
Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 6.6.148 with commit 6124bd785073659c99385094657b77382ebce11b
Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 6.12.101 with commit 2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4
Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 6.18.40 with commit 26b131b2d5b55a81ef6182769d28105a870c0eb2
Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 7.1.5 with commit 109241d9880488aafd8e104832b4d4859ad57244
Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 7.2-rc3 with commit 27f575836cfebbf872dec020428742b10650a955
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-72017
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/net/ethernet/cadence/macb_main.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/6124bd785073659c99385094657b77382ebce11b
https://git.kernel.org/stable/c/2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4
https://git.kernel.org/stable/c/26b131b2d5b55a81ef6182769d28105a870c0eb2
https://git.kernel.org/stable/c/109241d9880488aafd8e104832b4d4859ad57244
https://git.kernel.org/stable/c/27f575836cfebbf872dec020428742b10650a955
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-15 6:07 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-15 6:01 CVE-2026-72017: net: macb: drop in-flight Tx SKBs on close Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.