SB2026081633 - Off-by-one in Linux kernel qlogic qede driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Off-by-one (CVE-ID: CVE-2026-72339)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an off-by-one error in the qede_rx_build_skb() and qede_tpa_rx_build_skb() functions when handling a NULL return from qede_build_skb() under memory pressure. A local user can trigger memory pressure and network receive processing to cause memory corruption.
The issue can desynchronize the BD ring, which can corrupt DMA page reference counts and lead to SLUB freelist corruption.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/07be8b8adf91b7ada4c3dacce064d572a6066421
- https://git.kernel.org/stable/c/0bf78df2d3ecb1f4964ff42a7327d25845955153
- https://git.kernel.org/stable/c/1624aa100c0b218181aa74e3696a389b509298cb
- https://git.kernel.org/stable/c/814a5edac8c9fc04051808d5faaa93768e989281
- https://git.kernel.org/stable/c/982d6d6bc059c5dff37a2201c2f08c14bcfcbd20
- https://git.kernel.org/stable/c/a0a558ca7e75b49e71f8c545c30e8c005e6e4e2f
- https://git.kernel.org/stable/c/b066420e57f3402a52c998678b4678252ac9bb63
- https://git.kernel.org/stable/c/ecc05d4b20220a09c9c69584fc46ca55248a374a