AUGUST 22, 2026
Live Feed
Back to database
Case File

CVE-2026-68331

UNKNOWN · CVSS N/A EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's dpaa2 Ethernet driver, where a reference to a MAC endpoint device is not properly released during the disconnection process, leading to a memory leak. This can result in resource exhaustion over time, potentially impacting system stability and performance. Organizations using Linux systems with dpaa2 Ethernet drivers should prioritize addressing this issue to prevent potential disruptions in service.

CVE
CVE-2026-68331
Severity
UNKNOWN
CVSS
N/A
EPSS
0.17%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: dpaa2-eth: put MAC endpoint device on disconnect fsl_mc_get_endpoint() returns the MAC endpoint device with a reference taken through device_find_child(). The Ethernet connect path stores that device in mac->mc_dev and keeps it for the lifetime of the connected MAC object. However, the disconnect path only disconnects and closes the MAC before freeing the dpaa2_mac object. It does not drop the endpoint device reference stored in mac->mc_dev, so every successful connect leaks that device reference when the MAC is later disconnected. Drop the endpoint device reference after closing the MAC and before freeing the dpaa2_mac object.