{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72339","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-09T03:40:39.920Z","datePublished":"2026-08-15T05:55:46.480Z","dateUpdated":"2026-08-17T05:42:57.907Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:42:57.907Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nqede: fix off-by-one in BD ring consumption on build_skb failure\n\nqede_rx_build_skb() and qede_tpa_rx_build_skb() do not check for a\nNULL return from qede_build_skb(). When it returns NULL under memory\npressure, the functions still consume a BD from the ring before\nreturning NULL. The callers then recycle additional BDs, resulting in\none extra BD being consumed (off-by-one). This desynchronizes the BD\nring, which can corrupt DMA page reference counts and lead to SLUB\nfreelist corruption.\n\nCommit 4e910dbe3650 (\"qede: confirm skb is allocated before using\")\nadded a NULL check inside qede_build_skb() to prevent a NULL pointer\ndereference, but did not address the missing NULL checks in the\ncallers, making this off-by-one reachable.\n\nFix this by adding NULL checks for the return value of\nqede_build_skb() in both qede_rx_build_skb() and\nqede_tpa_rx_build_skb(), returning NULL immediately before any BD ring\nmanipulation."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The bug is in the qede NIC RX fastpath reached when remote Ethernet frames are received, hardware posts completion queue entries, and NAPI runs qede_poll() -> qede_rx_int() -> qede_rx_process_cqe()/qede_tpa_start() into qede_rx_build_skb() or qede_tpa_rx_build_skb().\nAC:L - An attacker can reliably trigger build_skb() NULL returns by flooding the interface with frames larger than rx_copybreak (256 bytes) to exhaust GFP_ATOMIC skb slab allocations, then the off-by-one BD consumption desynchronizes the ring without races or victim-specific state.\nPR:N - No local account, capability, or authentication is required; any unauthenticated remote host that can send IP/Ethernet traffic to a server using a Marvell/QLogic FastLinQ qede NIC can hit the vulnerable RX/TPA handlers.\nUI:N - Exploitation requires no victim interaction beyond normal network operation; packet reception, MSI-X interrupt handling, and NAPI polling process attacker-supplied frames automatically in kernel context.\nS:U - The flaw corrupts kernel heap metadata (DMA page refcounts and SLUB freelists) within the host kernel security boundary; it does not by itself cross VM, container, or IOMMU isolation boundaries.\nC:H - BD ring desynchronization corrupts DMA page reference counts and can corrupt SLUB freelists; this class of kernel heap corruption is exploitable for arbitrary kernel memory reads and information disclosure beyond a simple crash.\nI:H - SLUB freelist corruption from mismatched BD ring consumption enables arbitrary kernel memory writes and control-flow hijacking primitives, supporting local privilege escalation or arbitrary code execution in kernel context.\nA:H - Reference-count and SLUB corruption from the desynchronized BD ring can cause kernel BUG/oops/panic or a wedged RX datapath, resulting in complete loss of host availability on affected systems."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/qlogic/qede/qede_fp.c"],"versions":[{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"ecc05d4b20220a09c9c69584fc46ca55248a374a","status":"affected","versionType":"git"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"07be8b8adf91b7ada4c3dacce064d572a6066421","status":"affected","versionType":"git"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"1624aa100c0b218181aa74e3696a389b509298cb","status":"affected","versionType":"git"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"0bf78df2d3ecb1f4964ff42a7327d25845955153","status":"affected","versionType":"git"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"814a5edac8c9fc04051808d5faaa93768e989281","status":"affected","versionType":"git"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"b066420e57f3402a52c998678b4678252ac9bb63","status":"affected","versionType":"git"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"982d6d6bc059c5dff37a2201c2f08c14bcfcbd20","status":"affected","versionType":"git"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"a0a558ca7e75b49e71f8c545c30e8c005e6e4e2f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/qlogic/qede/qede_fp.c"],"versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ecc05d4b20220a09c9c69584fc46ca55248a374a"},{"url":"https://git.kernel.org/stable/c/07be8b8adf91b7ada4c3dacce064d572a6066421"},{"url":"https://git.kernel.org/stable/c/1624aa100c0b218181aa74e3696a389b509298cb"},{"url":"https://git.kernel.org/stable/c/0bf78df2d3ecb1f4964ff42a7327d25845955153"},{"url":"https://git.kernel.org/stable/c/814a5edac8c9fc04051808d5faaa93768e989281"},{"url":"https://git.kernel.org/stable/c/b066420e57f3402a52c998678b4678252ac9bb63"},{"url":"https://git.kernel.org/stable/c/982d6d6bc059c5dff37a2201c2f08c14bcfcbd20"},{"url":"https://git.kernel.org/stable/c/a0a558ca7e75b49e71f8c545c30e8c005e6e4e2f"}],"title":"qede: fix off-by-one in BD ring consumption on build_skb failure","x_generator":{"engine":"bippy-1.2.0"}}}}