SB20260816496 - Use of uninitialized resource in Linux kernel ethernet microchip driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of uninitialized resource (CVE-ID: CVE-2026-72037)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use of an uninitialized resource in lan743x_hardware_init() and lan743x_hs_syslock_acquire() when probing the device and reading strap status. A local user can trigger device initialization to cause a denial of service.
This issue can trip the spinlock debug check when CONFIG_DEBUG_SPINLOCK is enabled.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/39139b1c1c2b614096519b526112c726adb12ff0
- https://git.kernel.org/stable/c/6523daa6852b1bfef32ec7a105b0217e8a115687
- https://git.kernel.org/stable/c/99a6f37b113c46815deb160c5012073563679ef4
- https://git.kernel.org/stable/c/b6a93a42e0e61f0ba0005a942ee3bffb16c0574e
- https://git.kernel.org/stable/c/b99e890e6b32ffa11c145a16fefcf2c7137a9578
- https://git.kernel.org/stable/c/dfaefd9a7808736fcd2ed0de108f55c4badc15cc