ipmi: fix refcount leak in i_ipmi_request()

Summary

CVECVE-2026-72040
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:21:13 UTC
Updated2026-08-17 06:18:01 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ipmi: fix refcount leak in i_ipmi_request() When a caller provides a `supplied_recv` message to i_ipmi_request(), the function increments the user's `nr_msgs` reference count. If an error occurs later, the out_err cleanup path only frees the recv_msg if the function allocated it itself (i.e., !supplied_recv). In the supplied_recv case the cleanup is skipped, leaving the reference count elevated. The caller ipmi_request_supply_msgs() does not release the supplied_recv on error, so the reference is permanently leaked. Fix this by explicitly reverting the reference count operations when a supplied recv_msg with a valid user pointer is present in the error path: decrement nr_msgs and drop the user's kref.

Risk And Classification

EPSS: 0.002000000 probability, percentile 0.101750000 (date 2026-08-16)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 348121b29594d42d1635648fd3ed31dfa25351d5 9409e18ffe7378d202efe1cf69989df9f67b0369 git Not specified
CNA Linux Linux affected 53d6e403affbf6df2c859a0ea00ccfc1e72090ca e2a3b77df6aef031455dd83ea8ed4344b7dca1f9 git Not specified
CNA Linux Linux affected b52da4054ee0bf9ecb44996f2c83236ff50b3812 f5c5065963024390ddad51bd455d1adc710de575 git Not specified
CNA Linux Linux affected b52da4054ee0bf9ecb44996f2c83236ff50b3812 0fd23994ec8c5436d9f0b50848deb87ed933e6b3 git Not specified
CNA Linux Linux affected b52da4054ee0bf9ecb44996f2c83236ff50b3812 a3f3859cecacb64f18fd446271ece9a3b3f2d4de git Not specified
CNA Linux Linux affected f63723ca7d7623f9dae1990973cd158671f03c56 git Not specified
CNA Linux Linux affected 0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5 git Not specified
CNA Linux Linux affected 6.6.113 6.6.148 semver Not specified
CNA Linux Linux affected 6.12.54 6.12.101 semver Not specified
CNA Linux Linux affected 6.1.157 6.2 semver Not specified
CNA Linux Linux affected 6.17.4 6.18 semver Not specified
CNA Linux Linux affected 6.18 Not specified
CNA Linux Linux unaffected 6.18 semver Not specified
CNA Linux Linux unaffected 6.6.148 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.101 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/9409e18ffe7378d202efe1cf69989df9f67b0369 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e2a3b77df6aef031455dd83ea8ed4344b7dca1f9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f5c5065963024390ddad51bd455d1adc710de575 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/0fd23994ec8c5436d9f0b50848deb87ed933e6b3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a3f3859cecacb64f18fd446271ece9a3b3f2d4de 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report