net/mlx5: HWS, fix matcher leak on resize target setup failure
Summary
| CVE | CVE-2026-72032 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 06:21:12 UTC |
| Updated | 2026-08-17 06:18:00 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, fix matcher leak on resize target setup failure hws_bwc_matcher_move() allocates a replacement matcher before setting it as the resize target. If mlx5hws_matcher_resize_set_target() fails, the replacement matcher is not attached anywhere and is leaked. Fix the leak by destroying the replacement matcher before returning from the resize-target failure path. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1. An x86_64 allyesconfig build showed no new warnings. As we do not have a mlx5 HWS-capable device to test with, no runtime testing was able to be performed. |
Risk And Classification
EPSS: 0.002000000 probability, percentile 0.101650000 (date 2026-08-17)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 2111bb970c787b16b002dc726c1d296ce87a00fb a751ccdc6ea9bde154f25a5ba66926f462f96c19 git | Not specified |
| CNA | Linux | Linux | affected 2111bb970c787b16b002dc726c1d296ce87a00fb 1dce4f4bb3c1c02080b1a45bdd2abb2913a6642a git | Not specified |
| CNA | Linux | Linux | affected 2111bb970c787b16b002dc726c1d296ce87a00fb ae0265f0a95aaacef59d560a3e1ea36db8be9a52 git | Not specified |
| CNA | Linux | Linux | affected 2111bb970c787b16b002dc726c1d296ce87a00fb bb09d0e64ecaa0aa0f7d1133a1696ed74dead295 git | Not specified |
| CNA | Linux | Linux | affected 6.12 | Not specified |
| CNA | Linux | Linux | unaffected 6.12 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.101 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.40 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.5 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/bb09d0e64ecaa0aa0f7d1133a1696ed74dead295 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/1dce4f4bb3c1c02080b1a45bdd2abb2913a6642a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a751ccdc6ea9bde154f25a5ba66926f462f96c19 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ae0265f0a95aaacef59d560a3e1ea36db8be9a52 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.