-

CVE-2026-72040

ipmi: fix refcount leak in i_ipmi_request()

In the Linux kernel, the following vulnerability has been resolved:

ipmi: fix refcount leak in i_ipmi_request()

When a caller provides a `supplied_recv` message to i_ipmi_request(),
the function increments the user's `nr_msgs` reference count. If an
error occurs later, the out_err cleanup path only frees the recv_msg
if the function allocated it itself (i.e., !supplied_recv). In the
supplied_recv case the cleanup is skipped, leaving the reference count
elevated. The caller ipmi_request_supply_msgs() does not release the
supplied_recv on error, so the reference is permanently leaked.

Fix this by explicitly reverting the reference count operations when a
supplied recv_msg with a valid user pointer is present in the error
path: decrement nr_msgs and drop the user's kref.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f63723ca7d7623f9dae1990973cd158671f03c56
Version < 122ca6b2af714e114c9b872a48372ace31a9ab1f
Status affected
Version 348121b29594d42d1635648fd3ed31dfa25351d5
Version < 9409e18ffe7378d202efe1cf69989df9f67b0369
Status affected
Version 53d6e403affbf6df2c859a0ea00ccfc1e72090ca
Version < e2a3b77df6aef031455dd83ea8ed4344b7dca1f9
Status affected
Version b52da4054ee0bf9ecb44996f2c83236ff50b3812
Version < f5c5065963024390ddad51bd455d1adc710de575
Status affected
Version b52da4054ee0bf9ecb44996f2c83236ff50b3812
Version < 0fd23994ec8c5436d9f0b50848deb87ed933e6b3
Status affected
Version b52da4054ee0bf9ecb44996f2c83236ff50b3812
Version < a3f3859cecacb64f18fd446271ece9a3b3f2d4de
Status affected
Version 0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5
Status affected
Version 6.1.157
Version < 6.1.184
Status affected
Version 6.6.113
Version < 6.6.148
Status affected
Version 6.12.54
Version < 6.12.101
Status affected
Version 6.17.4
Version < 6.18
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.18
Status affected
Version 0
Version < 6.18
Status unaffected
Version <= 6.1.*
Version 6.1.184
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.101
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9409e18ffe7378d202efe1cf69989df9f67b0369
https://git.kernel.org/stable/c/e2a3b77df6aef031455dd83ea8ed4344b7dca1f9
https://git.kernel.org/stable/c/f5c5065963024390ddad51bd455d1adc710de575
https://git.kernel.org/stable/c/0fd23994ec8c5436d9f0b50848deb87ed933e6b3
https://git.kernel.org/stable/c/a3f3859cecacb64f18fd446271ece9a3b3f2d4de
https://git.kernel.org/stable/c/122ca6b2af714e114c9b872a48372ace31a9ab1f