From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-72059: net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
Date: Sat, 15 Aug 2026 15:02:18 +0900 [thread overview]
Message-ID: <2026081517-CVE-2026-72059-2fd9@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
t7xx_cldma_late_init() creates md_ctrl->gpd_dmapool before
initializing the TX and RX rings. If any ring initialization
fails, the error path frees the already initialized rings but
leaves the DMA pool allocated.
Destroy md_ctrl->gpd_dmapool on the late-init failure path
to avoid leaking the DMA pool.
The Linux kernel CVE team has assigned CVE-2026-72059 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.19 with commit 39d439047f1dc88f98b755d6f3a53a4ef8f0de21 and fixed in 6.1.178 with commit cef50f9f9045ff5e6a9d62c5110522df98fca645
Issue introduced in 5.19 with commit 39d439047f1dc88f98b755d6f3a53a4ef8f0de21 and fixed in 6.6.145 with commit fd01247bde1add970fae7f0003af085333a256e6
Issue introduced in 5.19 with commit 39d439047f1dc88f98b755d6f3a53a4ef8f0de21 and fixed in 6.12.97 with commit ebd84cb129fac7f7933628c40fccdfa8a62805de
Issue introduced in 5.19 with commit 39d439047f1dc88f98b755d6f3a53a4ef8f0de21 and fixed in 6.18.40 with commit e89b8829693e65217d587dceeaad4826c96c731b
Issue introduced in 5.19 with commit 39d439047f1dc88f98b755d6f3a53a4ef8f0de21 and fixed in 7.1.5 with commit 0c0a8c7821485f32bdb4923fb22f2dd501a27d8a
Issue introduced in 5.19 with commit 39d439047f1dc88f98b755d6f3a53a4ef8f0de21 and fixed in 7.2-rc1 with commit 2bd6f26d4ce1e87de4d736b1e8896daf3acf1c0e
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-72059
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/net/wwan/t7xx/t7xx_hif_cldma.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/cef50f9f9045ff5e6a9d62c5110522df98fca645
https://git.kernel.org/stable/c/fd01247bde1add970fae7f0003af085333a256e6
https://git.kernel.org/stable/c/ebd84cb129fac7f7933628c40fccdfa8a62805de
https://git.kernel.org/stable/c/e89b8829693e65217d587dceeaad4826c96c731b
https://git.kernel.org/stable/c/0c0a8c7821485f32bdb4923fb22f2dd501a27d8a
https://git.kernel.org/stable/c/2bd6f26d4ce1e87de4d736b1e8896daf3acf1c0e
reply other threads:[~2026-08-15 6:09 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026081517-CVE-2026-72059-2fd9@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.