CVE-2026-72032

Summary

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5: HWS, fix matcher leak on resize target setup failure

hws_bwc_matcher_move() allocates a replacement matcher before setting it as the resize target. If mlx5hws_matcher_resize_set_target() fails, the replacement matcher is not attached anywhere and is leaked.

Fix the leak by destroying the replacement matcher before returning from the resize-target failure path.

The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1.

An x86_64 allyesconfig build showed no new warnings. As we do not have a mlx5 HWS-capable device to test with, no runtime testing was able to be performed.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux2111bb970c787b16b002dc726c1d296ce87a00fb < a751ccdc6ea9bde154f25a5ba66926f462f96c19affected
LinuxLinux2111bb970c787b16b002dc726c1d296ce87a00fb < 1dce4f4bb3c1c02080b1a45bdd2abb2913a6642aaffected
LinuxLinux2111bb970c787b16b002dc726c1d296ce87a00fb < ae0265f0a95aaacef59d560a3e1ea36db8be9a52affected
LinuxLinux2111bb970c787b16b002dc726c1d296ce87a00fb < bb09d0e64ecaa0aa0f7d1133a1696ed74dead295affected
LinuxLinux6.12affected
LinuxLinux0 < 6.12unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References