CVE-2026-72109

Source
https://cve.org/CVERecord?id=CVE-2026-72109
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72109.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72109
Downstream
Published
2026-08-15T05:52:51.067Z
Modified
2026-08-18T03:56:20.071930300Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net: sparx5: unregister blocking notifier on init failure
Details

In the Linux kernel, the following vulnerability has been resolved:

net: sparx5: unregister blocking notifier on init failure

sparx5registernotifier_blocks() registers the switchdev blocking notifier before allocating the ordered workqueue. If the workqueue allocation fails, the error path unregisters the switchdev and netdevice notifiers, but leaves the blocking notifier registered.

Add a separate error label for the workqueue allocation failure path and unregister the switchdev blocking notifier there.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72109.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d6fce5141929697a27f029c633433d487f6f62cb
Fixed
fbc65b17508ed5464b7106e7fa5f15251ca1b603
Fixed
e5afc6d3fabdf1f605d63c4b34a3df6c359e81f3
Fixed
cf419c869e0d03aad4b6f4ecf0a813851930dfe7
Fixed
d6084c47389fd6978a5d66b0d58206a548c792a9
Fixed
8a3c44a003176282ee4306b7c96e5a536c6f0707
Fixed
17f113e7b622dc850992ade540181717de6a8561
Fixed
483be61b4a9a6df3b7cb277e8f189e082dee4cb8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72109.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72109.json"