CVE-2026-68328

Unknown

Last modified

CVE-2026-68328 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: nfp: Check resource mutex allocation nfp_cpp_resource_find() allocates a CPP mutex handle for the matching resource-table entry and then reports success. nfp_resource_try_acquire() immediately passes that handle to nfp_cpp_mutex_trylock(). However, nfp_cpp_mutex_alloc() returns NULL on failure.

Description

In the Linux kernel, the following vulnerability has been resolved: nfp: Check resource mutex allocation nfp_cpp_resource_find() allocates a CPP mutex handle for the matching resource-table entry and then reports success. nfp_resource_try_acquire() immediately passes that handle to nfp_cpp_mutex_trylock(). However, nfp_cpp_mutex_alloc() returns NULL on failure. If that happens for a matching table entry, the resource lookup still returns success and the following trylock dereferences a NULL mutex pointer while opening the resource. nfp_resource_acquire() already treats failure to allocate the table mutex as -ENOMEM. Do the same for the resource mutex and fail the lookup before publishing the rest of the resource handle. This issue was found by a static analysis checker and confirmed by manual source review.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= f01a2161577d31b14581e0db3bbbdfa963f145b6, < 6dbd428119cb1fd1b73cf6968c711f4ea964dc8b; >= f01a2161577d31b14581e0db3bbbdfa963f145b6, < cfa119aa781c4044dab5b4c1e5864600f53a26bc; >= f01a2161577d31b14581e0db3bbbdfa963f145b6, < 3b1d4fc3b73ea6faf008a0996ce6190c6e43efc3; >= f01a2161577d31b14581e0db3bbbdfa963f145b6, < a7dc30b6828c3a30252892827b12b676749f250f; >= f01a2161577d31b14581e0db3bbbdfa963f145b6, < a61b4db34a753bdf5c9e77a7f3d3dddd41dcfacc
LinuxLinux4.11

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68328?
In the Linux kernel, the following vulnerability has been resolved: nfp: Check resource mutex allocation nfp_cpp_resource_find() allocates a CPP mutex handle for the matching resource-table entry and then reports success. nfp_resource_try_acquire() immediately passes that handle to nfp_cpp_mutex_trylock(). However, nfp_cpp_mutex_alloc() returns NULL on failure. If that happens for a matching table entry, the resource lookup still returns success and the following trylock dereferences a NULL mutex pointer while opening the resource. nfp_resource_acquire() already treats failure to allocate the table mutex as -ENOMEM. Do the same for the resource mutex and fail the lookup before publishing the rest of the resource handle. This issue was found by a static analysis checker and confirmed by manual source review.
How severe is CVE-2026-68328?
Severity scoring for CVE-2026-68328 is pending analysis.
How do I fix CVE-2026-68328?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68328?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST