CVE-2026-72017: net: macb: drop in-flight Tx SKBs on close
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026081509-CVE-2026-72017-598c@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: net: macb: drop in-flight Tx SKBs on close The MACB driver has since forever leaked the outgoing SKBs that have not yet been marked as completed. They live in queue->tx_skb which gets freed without remorse nor checking. macb_free_consistent() gets called in a few codepaths, but only close will trigger the added expressions. In macb_open() and macb_alloc_consistent() failure cases, queues' tx_skb just got allocated and are empty. The Linux kernel CVE team has assigned CVE-2026-72017 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 6.6.148 with commit 6124bd785073659c99385094657b77382ebce11b Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 6.12.101 with commit 2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4 Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 6.18.40 with commit 26b131b2d5b55a81ef6182769d28105a870c0eb2 Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 7.1.5 with commit 109241d9880488aafd8e104832b4d4859ad57244 Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 7.2-rc3 with commit 27f575836cfebbf872dec020428742b10650a955 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-72017 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/ethernet/cadence/macb_main.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/6124bd785073659c99385094657b77382ebce11b https://git.kernel.org/stable/c/2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4 https://git.kernel.org/stable/c/26b131b2d5b55a81ef6182769d28105a870c0eb2 https://git.kernel.org/stable/c/109241d9880488aafd8e104832b4d4859ad57244 https://git.kernel.org/stable/c/27f575836cfebbf872dec020428742b10650a955