CVE-2026-72032
Last modified
CVE-2026-72032 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, fix matcher leak on resize target setup failure hws_bwc_matcher_move() allocates a replacement matcher before setting it as the resize target. If mlx5hws_matcher_resize_set_target() fails, the replacement matcher is not attached anywhere and is leaked. Fix the leak by destroying the replacement matcher before returning from the resize-target failure path. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, fix matcher leak on resize target setup failure hws_bwc_matcher_move() allocates a replacement matcher before setting it as the resize target. If mlx5hws_matcher_resize_set_target() fails, the replacement matcher is not attached anywhere and is leaked. Fix the leak by destroying the replacement matcher before returning from the resize-target failure path. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1. An x86_64 allyesconfig build showed no new warnings. As we do not have a mlx5 HWS-capable device to test with, no runtime testing was able to be performed.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 2111bb970c787b16b002dc726c1d296ce87a00fb, < a751ccdc6ea9bde154f25a5ba66926f462f96c19; >= 2111bb970c787b16b002dc726c1d296ce87a00fb, < 1dce4f4bb3c1c02080b1a45bdd2abb2913a6642a; >= 2111bb970c787b16b002dc726c1d296ce87a00fb, < ae0265f0a95aaacef59d560a3e1ea36db8be9a52; >= 2111bb970c787b16b002dc726c1d296ce87a00fb, < bb09d0e64ecaa0aa0f7d1133a1696ed74dead295 |
| Linux | Linux | 6.12 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72032?
How severe is CVE-2026-72032?
How do I fix CVE-2026-72032?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72027In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72028In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72029In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-7203A vulnerability was found in Totolink A8000RU 7.1cu.643_b202…9.8
- CVE-2026-72030In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72031In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72033In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-72034In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72035In the Linux kernel, the following vulnerability has been re…8.2
- CVE-2026-72036In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72037In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72038In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-72032?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
