CVE-2026-72307
In the Linux kernel, the following vulnerability has been resolved:
mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
When mlxsw_sp_vrs_lpm_tree_replace() fails after replacing some VRs, the error rollback loop does not correctly revert the preceding replacements. The loop decrements the index but fails to update the vr pointer, which still points to the VR that caused the failure. As a result, the condition and the rollback call always operate on the same VR, potentially calling mlxsw_sp_vr_lpm_tree_replace() multiple times on it while never rolling back the earlier VRs. Those VRs continue to hold a reference to new_tree acquired via mlxsw_sp_lpm_tree_hold(), leaking the reference count of new_tree.
Leer descripción completaMostrar menos
Fix by reinitializing vr inside the error loop with the updated index:
so that the loop correctly iterates over all VRs that were actually replaced.
Detalles técnicos trazas, registros y código del informe original
vr = &mlxsw_sp->router->vrs[i];
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/21cf8dc478a49e8de039c2739b1646a774cb1944
- https://git.kernel.org/stable/c/220d41bdce41fe5a39a7f419faab1e907b4093c2
- https://git.kernel.org/stable/c/3a2b47d1b4b3de54d030a7fdb6a322c970513ee3
- https://git.kernel.org/stable/c/7203ac71d3895fa5948b319dd724f0e1cffbc4a1
- https://git.kernel.org/stable/c/8adebf07b46df79a0e49a6d4ae384f0db7c91db6
- https://git.kernel.org/stable/c/9e4a6185679922305ea1df68403f00ccc512656b
- https://git.kernel.org/stable/c/c2c75c45b54f3b12eafb28a4eb47f8821512c1aa
- https://git.kernel.org/stable/c/f6454a5fbf2224ad30ec70e686a6c592561da1f2
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72307",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"lessThan": "c2c75c45b54f3b12eafb28a4eb47f8821512c1aa",
"versionType": "git"
},
{
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"lessThan": "7203ac71d3895fa5948b319dd724f0e1cffbc4a1",
"versionType": "git"
},
{
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"lessThan": "f6454a5fbf2224ad30ec70e686a6c592561da1f2",
"versionType": "git"
},
{
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"lessThan": "220d41bdce41fe5a39a7f419faab1e907b4093c2",
"versionType": "git"
},
{
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"lessThan": "9e4a6185679922305ea1df68403f00ccc512656b",
"versionType": "git"
},
{
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"lessThan": "3a2b47d1b4b3de54d030a7fdb6a322c970513ee3",
"versionType": "git"
},
{
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"lessThan": "8adebf07b46df79a0e49a6d4ae384f0db7c91db6",
"versionType": "git"
},
{
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"lessThan": "21cf8dc478a49e8de039c2739b1646a774cb1944",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.14",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:22:03.440",
"references": [
{
"url": "https://git.kernel.org/stable/c/21cf8dc478a49e8de039c2739b1646a774cb1944",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/220d41bdce41fe5a39a7f419faab1e907b4093c2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3a2b47d1b4b3de54d030a7fdb6a322c970513ee3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7203ac71d3895fa5948b319dd724f0e1cffbc4a1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8adebf07b46df79a0e49a6d4ae384f0db7c91db6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9e4a6185679922305ea1df68403f00ccc512656b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c2c75c45b54f3b12eafb28a4eb47f8821512c1aa",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f6454a5fbf2224ad30ec70e686a6c592561da1f2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()\n\nWhen mlxsw_sp_vrs_lpm_tree_replace() fails after replacing some VRs,\nthe error rollback loop does not correctly revert the preceding\nreplacements. The loop decrements the index but fails to update the\nvr pointer, which still points to the VR that caused the failure. As\na result, the condition and the rollback call always operate on the\nsame VR, potentially calling mlxsw_sp_vr_lpm_tree_replace() multiple\ntimes on it while never rolling back the earlier VRs. Those VRs\ncontinue to hold a reference to new_tree acquired via\nmlxsw_sp_lpm_tree_hold(), leaking the reference count of new_tree.\n\nFix by reinitializing vr inside the error loop with the updated index:\n\n\tvr = &mlxsw_sp->router->vrs[i];\n\nso that the loop correctly iterates over all VRs that were actually\nreplaced."
}
],
"lastModified": "2026-08-17T06:18:33.787",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}