SB20260816503 - Memory leak in Linux kernel octeontx2 nic driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Memory leak (CVE-ID: CVE-2026-72023)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a memory leak in otx2_init_hw_resources() and the SQ resource unwind path when handling initialization failures. A local user can trigger an initialization failure to cause a denial of service.
Exploitation requires access to a system using the OcteonTX2 PF driver.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/148d7ec0a3a98839c320e6cdd112e2e88bfb091b
- https://git.kernel.org/stable/c/23d917acd9c9a9fd999688ec3fdde7aa58ab8a14
- https://git.kernel.org/stable/c/5df30f05db96552903680a17f858d250dfd9e86e
- https://git.kernel.org/stable/c/5e023fe2569e630ba23b5558ebe4bf4837af4d16
- https://git.kernel.org/stable/c/62e7df6d042aeebd5efb581074e28865c04477be