Use of uninitialized resource in Linux kernel - CVE-2026-72037
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use of an uninitialized resource in lan743x_hardware_init() and lan743x_hs_syslock_acquire() when probing the device and reading strap status. A local user can trigger device initialization to cause a denial of service.
This issue can trip the spinlock debug check when CONFIG_DEBUG_SPINLOCK is enabled.
Affected software
How to mitigate CVE-2026-72037
External References
- https://git.kernel.org/stable/c/39139b1c1c2b614096519b526112c726adb12ff0
- https://git.kernel.org/stable/c/6523daa6852b1bfef32ec7a105b0217e8a115687
- https://git.kernel.org/stable/c/99a6f37b113c46815deb160c5012073563679ef4
- https://git.kernel.org/stable/c/b6a93a42e0e61f0ba0005a942ee3bffb16c0574e
- https://git.kernel.org/stable/c/b99e890e6b32ffa11c145a16fefcf2c7137a9578
- https://git.kernel.org/stable/c/dfaefd9a7808736fcd2ed0de108f55c4badc15cc