CVE-2026-72040
CVE CVE-2026-72040EUVD EUVD-2026-58998Published 2026-08-15T05:51:59.000ZLast changed 2026-08-17T05:07:06.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ipmi: fix refcount leak in i_ipmi_request() When a caller provides a `supplied_recv` message to i_ipmi_request(), the function increments the user's `nr_msgs` reference count. If an error occurs later, the out_err cleanup path only frees the recv_msg if the function allocated it itself (i.e., !supplied_recv). In the supplied_recv case the cleanup is skipped, leaving the reference count elevated. The caller ipmi_request_supply_msgs() does not release the supplied_recv on error, so the reference is permanently leaked. Fix this by explicitly reverting the reference count operations when a supplied recv_msg with a valid user pointer is present in the error path: decrement nr_msgs and drop the user's kref.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5; patch: 0; 53d6e403affbf6df2c859a0ea00ccfc1e72090ca <e2a3b77df6aef031455dd83ea8ed4344b7dca1f9; f63723ca7d7623f9dae1990973cd158671f03c56; 6.6.113 <6.6.148; patch: 6.6.148; patch: 6.18.40; patch: 6.12.101; 6.18; 6.12.54 <6.12.101; patch: 7.2; 6.17.4 <6.18; b52da4054ee0bf9ecb44996f2c83236ff50b3812 <a3f3859cecacb64f18fd446271ece9a3b3f2d4de; b52da4054ee0bf9ecb44996f2c83236ff50b3812 <0fd23994ec8c5436d9f0b50848deb87ed933e6b3; 6.1.157 <6.2; patch: 7.1.5; b52da4054ee0bf9ecb44996f2c83236ff50b3812 <f5c5065963024390ddad51bd455d1adc710de575; 348121b29594d42d1635648fd3ed31dfa25351d5 <9409e18ffe7378d202efe1cf69989df9f67b0369
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.