7.8
CVE-2026-72042
- EPSS 0.16%
- Veröffentlicht 15.08.2026 05:52:01
- Zuletzt bearbeitet 17.08.2026 06:18:02
- Erkennungen
ipmi: Fix user refcount underflow in event delivery
In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix user refcount underflow in event delivery ipmi_alloc_recv_msg(user) takes the temporary user reference owned by the receive message, and ipmi_free_recv_msg() drops it again. If event delivery fails after allocating receive messages for earlier users, handle_read_event_rsp() rolls those messages back with ipmi_free_recv_msg(). That rollback path still drops user->refcount explicitly after freeing each message. The extra put can free a user that remains linked on intf->users, so later event delivery may dereference a freed user or trip refcount_t's addition-on-zero warning when ipmi_alloc_recv_msg() tries to acquire another reference. Remove the stale explicit put and the now-dead user assignment. Keep the list_del() and ipmi_free_recv_msg() calls; they are the required rollback operations.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
b52da4054ee0bf9ecb44996f2c83236ff50b3812
Version <
ddbb6e3dc9bb4743de686aa1598c31e745cee76b
Status
affected
Version
b52da4054ee0bf9ecb44996f2c83236ff50b3812
Version <
7be349d4fcc5e065295b83418a22d27a68afbdb6
Status
affected
Version
b52da4054ee0bf9ecb44996f2c83236ff50b3812
Version <
6aa9e61c46465d231e9beddf56af7effd71be682
Status
affected
Version
f63723ca7d7623f9dae1990973cd158671f03c56
Status
affected
Version
348121b29594d42d1635648fd3ed31dfa25351d5
Status
affected
Version
53d6e403affbf6df2c859a0ea00ccfc1e72090ca
Status
affected
Version
0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5
Status
affected
Version
6.1.157
Version <
6.2
Status
affected
Version
6.6.113
Version <
6.7
Status
affected
Version
6.12.54
Version <
6.13
Status
affected
Version
6.17.4
Version <
6.18
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.18
Status
affected
Version
0
Version <
6.18
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.058 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/ddbb6e3dc9bb4743de686aa1598c31e745cee76b
https://git.kernel.org/stable/c/7be349d4fcc5e065295b83418a22d27a68afbdb6
https://git.kernel.org/stable/c/6aa9e61c46465d231e9beddf56af7effd71be682