-

CVE-2026-68328

nfp: Check resource mutex allocation

In the Linux kernel, the following vulnerability has been resolved:

nfp: Check resource mutex allocation

nfp_cpp_resource_find() allocates a CPP mutex handle for the matching
resource-table entry and then reports success.  nfp_resource_try_acquire()
immediately passes that handle to nfp_cpp_mutex_trylock().

However, nfp_cpp_mutex_alloc() returns NULL on failure.  If that happens
for a matching table entry, the resource lookup still returns success and
the following trylock dereferences a NULL mutex pointer while opening the
resource.

nfp_resource_acquire() already treats failure to allocate the table mutex
as -ENOMEM.  Do the same for the resource mutex and fail the lookup before
publishing the rest of the resource handle.

This issue was found by a static analysis checker and confirmed by
manual source review.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f01a2161577d31b14581e0db3bbbdfa963f145b6
Version < 18737a48acc87e4cbe41d6fea9a3f44eae490e24
Status affected
Version f01a2161577d31b14581e0db3bbbdfa963f145b6
Version < 423523f96a681428ce6e214eaf47f0d8242319de
Status affected
Version f01a2161577d31b14581e0db3bbbdfa963f145b6
Version < 0dbd85a8cc35c14bd26e686fa5fae8c64a7958ae
Status affected
Version f01a2161577d31b14581e0db3bbbdfa963f145b6
Version < 6dbd428119cb1fd1b73cf6968c711f4ea964dc8b
Status affected
Version f01a2161577d31b14581e0db3bbbdfa963f145b6
Version < cfa119aa781c4044dab5b4c1e5864600f53a26bc
Status affected
Version f01a2161577d31b14581e0db3bbbdfa963f145b6
Version < 3b1d4fc3b73ea6faf008a0996ce6190c6e43efc3
Status affected
Version f01a2161577d31b14581e0db3bbbdfa963f145b6
Version < a7dc30b6828c3a30252892827b12b676749f250f
Status affected
Version f01a2161577d31b14581e0db3bbbdfa963f145b6
Version < a61b4db34a753bdf5c9e77a7f3d3dddd41dcfacc
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.11
Status affected
Version 0
Version < 4.11
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.075
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/6dbd428119cb1fd1b73cf6968c711f4ea964dc8b
https://git.kernel.org/stable/c/cfa119aa781c4044dab5b4c1e5864600f53a26bc
https://git.kernel.org/stable/c/3b1d4fc3b73ea6faf008a0996ce6190c6e43efc3
https://git.kernel.org/stable/c/a7dc30b6828c3a30252892827b12b676749f250f
https://git.kernel.org/stable/c/a61b4db34a753bdf5c9e77a7f3d3dddd41dcfacc
https://git.kernel.org/stable/c/0dbd85a8cc35c14bd26e686fa5fae8c64a7958ae
https://git.kernel.org/stable/c/18737a48acc87e4cbe41d6fea9a3f44eae490e24
https://git.kernel.org/stable/c/423523f96a681428ce6e214eaf47f0d8242319de