net/mlx5: HWS, fix matcher leak on resize target setup failure
Published Aug 15, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.21%
Description
hws_bwc_matcher_move() allocates a replacement matcher before setting it as the resize target. If mlx5hws_matcher_resize_set_target() fails, the replacement matcher is not attached anywhere and is leaked.
Fix the leak by destroying the replacement matcher before returning from the resize-target failure path.
The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1.
An x86_64 allyesconfig build showed no new warnings. As we do not have a mlx5 HWS-capable device to test with, no runtime testing was able to be performed.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 6.12
Unaffected
- ≥ 0, < 6.12
- ≥ 6.12.101, ≤ 6.12.*
- ≥ 6.18.40, ≤ 6.18.*
- ≥ 7.1.5, ≤ 7.1.*
- 7.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-72032 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2516265 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-58990 Advisory
- https://git.kernel.org/stable/c/1dce4f4bb3c1c02080b1a45bdd2abb2913a6642a
- https://git.kernel.org/stable/c/a751ccdc6ea9bde154f25a5ba66926f462f96c19
- https://git.kernel.org/stable/c/ae0265f0a95aaacef59d560a3e1ea36db8be9a52
- https://git.kernel.org/stable/c/bb09d0e64ecaa0aa0f7d1133a1696ed74dead295
- https://lore.kernel.org/linux-cve-announce/2026081512-CVE-2026-72032-bc57@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-72032
- https://www.cve.org/CVERecord?id=CVE-2026-72032
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data