CVE-2026-72006
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: free mlx5_st_idx_data on final dealloc
Workloads that repeatedly allocate and release mkeys carrying TPH steering-tag hints (e.g. churning RDMA MRs) leak one struct mlx5_st_idx_data per cycle; kmemleak flags it as unreferenced and the kmalloc slab grows over time.
When the last reference to an ST table entry is dropped, mlx5_st_dealloc_index() removed the entry from idx_xa but the backing mlx5_st_idx_data allocation was never freed.
Free idx_data after the xa_erase() so the lifetime of the bookkeeping struct matches the lifetime of the ST entry it tracks.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72006",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "888a7776f4fb04c19bec70c737c61c2f383c6b1e",
"lessThan": "262da8b6ea03d01ee7ed01ad309e4c89941f6b14",
"versionType": "git"
},
{
"status": "affected",
"version": "888a7776f4fb04c19bec70c737c61c2f383c6b1e",
"lessThan": "6eb4cf2fa8997f62c11e0006dc010a1fd89c5a75",
"versionType": "git"
},
{
"status": "affected",
"version": "888a7776f4fb04c19bec70c737c61c2f383c6b1e",
"lessThan": "df6134b527a88b3e65ba6ae5073664af091d5fd2",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/lib/st.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/lib/st.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:20:59.250",
"references": [
{
"url": "https://git.kernel.org/stable/c/262da8b6ea03d01ee7ed01ad309e4c89941f6b14",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6eb4cf2fa8997f62c11e0006dc010a1fd89c5a75",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/df6134b527a88b3e65ba6ae5073664af091d5fd2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: free mlx5_st_idx_data on final dealloc\n\nWorkloads that repeatedly allocate and release mkeys carrying TPH\nsteering-tag hints (e.g. churning RDMA MRs) leak one\nstruct mlx5_st_idx_data per cycle; kmemleak flags it as unreferenced\nand the kmalloc slab grows over time.\n\nWhen the last reference to an ST table entry is dropped,\nmlx5_st_dealloc_index() removed the entry from idx_xa but the backing\nmlx5_st_idx_data allocation was never freed.\n\nFree idx_data after the xa_erase() so the lifetime of the bookkeeping\nstruct matches the lifetime of the ST entry it tracks."
}
],
"lastModified": "2026-08-17T06:17:58.083",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}