CVE-2026-72042
CVE CVE-2026-72042EUVD EUVD-2026-59000Published 2026-08-15T05:52:01.000ZLast changed 2026-08-17T05:39:41.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix user refcount underflow in event delivery ipmi_alloc_recv_msg(user) takes the temporary user reference owned by the receive message, and ipmi_free_recv_msg() drops it again. If event delivery fails after allocating receive messages for earlier users, handle_read_event_rsp() rolls those messages back with ipmi_free_recv_msg(). That rollback path still drops user->refcount explicitly after freeing each message. The extra put can free a user that remains linked on intf->users, so later event delivery may dereference a freed user or trip refcount_t's addition-on-zero warning when ipmi_alloc_recv_msg() tries to acquire another reference. Remove the stale explicit put and the now-dead user assignment. Keep the list_del() and ipmi_free_recv_msg() calls; they are the required rollback operations.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 348121b29594d42d1635648fd3ed31dfa25351d5; b52da4054ee0bf9ecb44996f2c83236ff50b3812 <ddbb6e3dc9bb4743de686aa1598c31e745cee76b; 0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5; b52da4054ee0bf9ecb44996f2c83236ff50b3812 <7be349d4fcc5e065295b83418a22d27a68afbdb6; patch: 7.2; 6.6.113 <6.7; 6.12.54 <6.13; patch: 6.18.40; f63723ca7d7623f9dae1990973cd158671f03c56; 53d6e403affbf6df2c859a0ea00ccfc1e72090ca; b52da4054ee0bf9ecb44996f2c83236ff50b3812 <6aa9e61c46465d231e9beddf56af7effd71be682; 6.18; patch: 0; patch: 7.1.5; 6.17.4 <6.18; 6.1.157 <6.2
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.