CVE-2026-72499

Summary

In the Linux kernel, the following vulnerability has been resolved:

RDMA/bnxt_re: Free CQ toggle page after firmware teardown

Free the toggle page only after firmware teardown completes so that an NQ interrupt arriving during bnxt_qplib_destroy_cq() won't write the toggle value to an already-freed page. Move free_page() after bnxt_qplib_destroy_cq.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxe275919d96693c5ca964b20d73a33d52a7e57f04 < b193854675ecad43b4d69c304c1b6a90b206cc99affected
LinuxLinuxe275919d96693c5ca964b20d73a33d52a7e57f04 < bb45e06f9914ca64ac95341a80a0c20bb8dd46a9affected
LinuxLinux6.8affected
LinuxLinux0 < 6.8unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References