mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
Published Aug 15, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.22%
Description
When mlxsw_sp_vrs_lpm_tree_replace() fails after replacing some VRs, the error rollback loop does not correctly revert the preceding replacements. The loop decrements the index but fails to update the vr pointer, which still points to the VR that caused the failure. As a result, the condition and the rollback call always operate on the same VR, potentially calling mlxsw_sp_vr_lpm_tree_replace() multiple times on it while never rolling back the earlier VRs. Those VRs continue to hold a reference to new_tree acquired via mlxsw_sp_lpm_tree_hold(), leaking the reference count of new_tree.
Fix by reinitializing vr inside the error loop with the updated index:
vr = &mlxsw_sp->router->vrs[i];
so that the loop correctly iterates over all VRs that were actually replaced.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.14StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.14
- Version 5.10.261StatusunaffectedConstraints<=5.10.*
- Version 5.15.212StatusunaffectedConstraints<=5.15.*
- Version 6.1.178StatusunaffectedConstraints<=6.1.*
- Version 6.12.97StatusunaffectedConstraints<=6.12.*
- Version 6.18.40StatusunaffectedConstraints<=6.18.*
- Version 6.6.145StatusunaffectedConstraints<=6.6.*
- Version 7.1.5StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2026-72307 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2516566 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-59206 Advisory
- https://git.kernel.org/stable/c/21cf8dc478a49e8de039c2739b1646a774cb1944
- https://git.kernel.org/stable/c/220d41bdce41fe5a39a7f419faab1e907b4093c2
- https://git.kernel.org/stable/c/3a2b47d1b4b3de54d030a7fdb6a322c970513ee3
- https://git.kernel.org/stable/c/7203ac71d3895fa5948b319dd724f0e1cffbc4a1
- https://git.kernel.org/stable/c/8adebf07b46df79a0e49a6d4ae384f0db7c91db6
- https://git.kernel.org/stable/c/9e4a6185679922305ea1df68403f00ccc512656b
- https://git.kernel.org/stable/c/c2c75c45b54f3b12eafb28a4eb47f8821512c1aa
- https://git.kernel.org/stable/c/f6454a5fbf2224ad30ec70e686a6c592561da1f2
- https://lore.kernel.org/linux-cve-announce/2026081503-CVE-2026-72307-d091@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-72307
- https://www.cve.org/CVERecord?id=CVE-2026-72307
Change history (0)
No recorded changes yet.