CVE-2026-72307
CVE CVE-2026-72307EUVD EUVD-2026-59206Published 2026-08-15T05:55:24.000ZLast changed 2026-08-17T05:12:11.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() When mlxsw_sp_vrs_lpm_tree_replace() fails after replacing some VRs, the error rollback loop does not correctly revert the preceding replacements. The loop decrements the index but fails to update the vr pointer, which still points to the VR that caused the failure. As a result, the condition and the rollback call always operate on the same VR, potentially calling mlxsw_sp_vr_lpm_tree_replace() multiple times on it while never rolling back the earlier VRs. Those VRs continue to hold a reference to new_tree acquired via mlxsw_sp_lpm_tree_hold(), leaking the reference count of new_tree. Fix by reinitializing vr inside the error loop with the updated index: vr = &mlxsw_sp->router->vrs[i]; so that the loop correctly iterates over all VRs that were actually replaced.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 4.14; fc922bb0dd9406dd9897fd47df958789891c380e <c2c75c45b54f3b12eafb28a4eb47f8821512c1aa; patch: 6.18.40; patch: 6.6.145; patch: 7.2; patch: 6.12.97; patch: 7.1.5; fc922bb0dd9406dd9897fd47df958789891c380e <3a2b47d1b4b3de54d030a7fdb6a322c970513ee3; patch: 0; fc922bb0dd9406dd9897fd47df958789891c380e <8adebf07b46df79a0e49a6d4ae384f0db7c91db6; fc922bb0dd9406dd9897fd47df958789891c380e <220d41bdce41fe5a39a7f419faab1e907b4093c2; fc922bb0dd9406dd9897fd47df958789891c380e <f6454a5fbf2224ad30ec70e686a6c592561da1f2; patch: 6.1.178; fc922bb0dd9406dd9897fd47df958789891c380e <7203ac71d3895fa5948b319dd724f0e1cffbc4a1; patch: 5.10.261; fc922bb0dd9406dd9897fd47df958789891c380e <21cf8dc478a49e8de039c2739b1646a774cb1944; fc922bb0dd9406dd9897fd47df958789891c380e <9e4a6185679922305ea1df68403f00ccc512656b; patch: 5.15.212
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.