SB20260816465 - Use-after-free in Linux kernel core en_accel driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-72072)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in mlx5e MACsec RX offload handling when deleting and processing offloaded MACsec RX SC entries concurrently. A local user can trigger concurrent RX SC deletion and RX datapath processing to cause a denial of service.
The issue affects the RX datapath under RCU lookup and reference handling of metadata_dst objects.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/088873af13590ebde10de2ade847f57a05ec61c6
- https://git.kernel.org/stable/c/218cc15a4c907659ad4b0e68c535c61594311205
- https://git.kernel.org/stable/c/4a5073b7b30243658f58b2d2d35a823da7fd34d9
- https://git.kernel.org/stable/c/b1a4d0c568bbb52c7c04f4fce3c097dae89ed6cb
- https://git.kernel.org/stable/c/de74d8fd10291763d97b218f09adcc7513c975e4
- https://git.kernel.org/stable/c/ed3cc4218070d6b98bf5fb456dccae424fd38c4f