Memory leak in Linux kernel - CVE-2026-72039
Published: August 16, 2026
Vulnerability identifier: #VU143562
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72039
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a memory leak in bnx2x_alloc_mem_bp() when handling allocation failures for fp[i].tpa_info. A local user can trigger allocation failure conditions to cause a denial of service.
Affected software
Linux kernel
How to mitigate CVE-2026-72039
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/356077547b1afa34a8ebae77176a577631a89041
- https://git.kernel.org/stable/c/5576ee19a6a4aa111c61ce974e70bb79e7bb3952
- https://git.kernel.org/stable/c/58594ed2a2f859ffb93edbbfa4aabb7739bea383
- https://git.kernel.org/stable/c/6c98ccdb9a0967e04a7b1866eb0d97c0c8c0e403
- https://git.kernel.org/stable/c/6d46eaa1e4c078ad674908e24b86e431a7fd4b15
- https://git.kernel.org/stable/c/7d8d454b5d24dbad346cd57ef315e7bf1ee8e856
- https://git.kernel.org/stable/c/a986fde914d88af47eb78fd29c5d1af7952c3500
- https://git.kernel.org/stable/c/c51b280b9cd3c9e97bf2cde33bb795c511f09669