CVE-2026-72017: net: macb: drop in-flight Tx SKBs on close

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026081509-CVE-2026-72017-598c@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

net: macb: drop in-flight Tx SKBs on close

The MACB driver has since forever leaked the outgoing SKBs that
have not yet been marked as completed. They live in queue->tx_skb
which gets freed without remorse nor checking.

macb_free_consistent() gets called in a few codepaths, but only close will
trigger the added expressions. In macb_open() and macb_alloc_consistent()
failure cases, queues' tx_skb just got allocated and are empty.

The Linux kernel CVE team has assigned CVE-2026-72017 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 6.6.148 with commit 6124bd785073659c99385094657b77382ebce11b
	Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 6.12.101 with commit 2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4
	Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 6.18.40 with commit 26b131b2d5b55a81ef6182769d28105a870c0eb2
	Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 7.1.5 with commit 109241d9880488aafd8e104832b4d4859ad57244
	Issue introduced in 2.6.20 with commit 89e5785fc8a6b9eafd37f2318a9a76d479c796be and fixed in 7.2-rc3 with commit 27f575836cfebbf872dec020428742b10650a955

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-72017
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/net/ethernet/cadence/macb_main.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/6124bd785073659c99385094657b77382ebce11b
	https://git.kernel.org/stable/c/2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4
	https://git.kernel.org/stable/c/26b131b2d5b55a81ef6182769d28105a870c0eb2
	https://git.kernel.org/stable/c/109241d9880488aafd8e104832b4d4859ad57244
	https://git.kernel.org/stable/c/27f575836cfebbf872dec020428742b10650a955
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.