{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72109","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-09T03:40:39.906Z","datePublished":"2026-08-15T05:52:51.067Z","dateUpdated":"2026-08-17T05:40:22.667Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:40:22.667Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sparx5: unregister blocking notifier on init failure\n\nsparx5_register_notifier_blocks() registers the switchdev blocking\nnotifier before allocating the ordered workqueue. If the workqueue\nallocation fails, the error path unregisters the switchdev and netdevice\nnotifiers, but leaves the blocking notifier registered.\n\nAdd a separate error label for the workqueue allocation failure path and\nunregister the switchdev blocking notifier there."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation reaches sparx5_switchdev_blocking_event through global switchdev blocking notifier callbacks fired by local bridge/VLAN/MDB configuration via rtnetlink, not by processing remote packets on Sparx5 switch ports.\nAC:L - After a sparx5 probe workqueue ENOMEM leaves the blocking notifier registered and devm frees sparx5, an attacker can reliably trigger call_switchdev_blocking_notifiers with ordinary bridge or VLAN netlink operations without uncontrollable races.\nPR:L - Triggering switchdev blocking events requires CAP_NET_ADMIN for bridge/VLAN changes; unprivileged users can obtain that capability in user/network namespaces and invoke the global notifier chain from their own bridge configuration.\nUI:N - No victim interaction is required beyond the attacker performing network administration operations; no user must open files, mount filesystems, or click anything to reach the stale notifier callback.\nS:U - The use-after-free corrupts kernel memory within the same kernel security authority on Sparx5/LAN969x switch platforms, enabling local privilege escalation but not VM escape or other cross-authority boundary bypass by itself.\nC:H - The leaked switchdev_blocking_nb remains on a global chain after devm frees the containing sparx5 structure; sparx5_switchdev_blocking_event dereferences it via container_of, creating a use-after-free that can disclose kernel memory.\nI:H - UAF callbacks such as sparx5_handle_port_vlan_add and MDB handlers dereference freed sparx5 state and can write through sparx5_mact_learn and related hardware programming, enabling memory corruption and potential arbitrary code execution.\nA:H - Dereferencing freed notifier_block and sparx5 structures during global switchdev blocking events can cause kernel oops, panic, or hang, disrupting availability on enterprise, industrial, and automotive Sparx5-managed switch systems."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/microchip/sparx5/sparx5_switchdev.c"],"versions":[{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"fbc65b17508ed5464b7106e7fa5f15251ca1b603","status":"affected","versionType":"git"},{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"e5afc6d3fabdf1f605d63c4b34a3df6c359e81f3","status":"affected","versionType":"git"},{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"cf419c869e0d03aad4b6f4ecf0a813851930dfe7","status":"affected","versionType":"git"},{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"d6084c47389fd6978a5d66b0d58206a548c792a9","status":"affected","versionType":"git"},{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"8a3c44a003176282ee4306b7c96e5a536c6f0707","status":"affected","versionType":"git"},{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"17f113e7b622dc850992ade540181717de6a8561","status":"affected","versionType":"git"},{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"483be61b4a9a6df3b7cb277e8f189e082dee4cb8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/microchip/sparx5/sparx5_switchdev.c"],"versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/fbc65b17508ed5464b7106e7fa5f15251ca1b603"},{"url":"https://git.kernel.org/stable/c/e5afc6d3fabdf1f605d63c4b34a3df6c359e81f3"},{"url":"https://git.kernel.org/stable/c/cf419c869e0d03aad4b6f4ecf0a813851930dfe7"},{"url":"https://git.kernel.org/stable/c/d6084c47389fd6978a5d66b0d58206a548c792a9"},{"url":"https://git.kernel.org/stable/c/8a3c44a003176282ee4306b7c96e5a536c6f0707"},{"url":"https://git.kernel.org/stable/c/17f113e7b622dc850992ade540181717de6a8561"},{"url":"https://git.kernel.org/stable/c/483be61b4a9a6df3b7cb277e8f189e082dee4cb8"}],"title":"net: sparx5: unregister blocking notifier on init failure","x_generator":{"engine":"bippy-1.2.0"}}}}