CVE-2026-72499

Source
https://cve.org/CVERecord?id=CVE-2026-72499
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72499.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72499
Downstream
Published
2026-08-15T05:57:31.696Z
Modified
2026-08-18T03:56:27.550010619Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
RDMA/bnxt_re: Free CQ toggle page after firmware teardown
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/bnxt_re: Free CQ toggle page after firmware teardown

Free the toggle page only after firmware teardown completes so that an NQ interrupt arriving during bnxtqplibdestroycq() won't write the toggle value to an already-freed page. Move freepage() after bnxtqplibdestroy_cq.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72499.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e275919d96693c5ca964b20d73a33d52a7e57f04
Fixed
b193854675ecad43b4d69c304c1b6a90b206cc99
Fixed
bb45e06f9914ca64ac95341a80a0c20bb8dd46a9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72499.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72499.json"