CVE-2026-72032

Source
https://cve.org/CVERecord?id=CVE-2026-72032
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72032.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72032
Downstream
Published
2026-08-15T05:51:54.461Z
Modified
2026-08-18T03:31:03.287151962Z
Summary
net/mlx5: HWS, fix matcher leak on resize target setup failure
Details

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5: HWS, fix matcher leak on resize target setup failure

hwsbwcmatchermove() allocates a replacement matcher before setting it as the resize target. If mlx5hwsmatcherresizeset_target() fails, the replacement matcher is not attached anywhere and is leaked.

Fix the leak by destroying the replacement matcher before returning from the resize-target failure path.

The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1.

An x86_64 allyesconfig build showed no new warnings. As we do not have a mlx5 HWS-capable device to test with, no runtime testing was able to be performed.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72032.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2111bb970c787b16b002dc726c1d296ce87a00fb
Fixed
a751ccdc6ea9bde154f25a5ba66926f462f96c19
Fixed
1dce4f4bb3c1c02080b1a45bdd2abb2913a6642a
Fixed
ae0265f0a95aaacef59d560a3e1ea36db8be9a52
Fixed
bb09d0e64ecaa0aa0f7d1133a1696ed74dead295

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72032.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72032.json"