AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72308

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's mlxsw component, specifically in the mlxsw_sp_port_lag_join() function, where a reference count leak occurs if mlxsw_sp_port_lag_index_get() fails. This oversight can lead to resource exhaustion over time, potentially impacting system stability. Linux kernel maintainers and developers utilizing the mlxsw component should prioritize applying the fix to prevent potential performance degradation.

CVE
CVE-2026-72308
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() When mlxsw_sp_port_lag_index_get() fails, mlxsw_sp_port_lag_join() returns an error without releasing the lag reference obtained by the earlier mlxsw_sp_lag_get(). All other error paths in the function jump to the cleanup label that ends with mlxsw_sp_lag_put(), so this is a single missed release. Fix the leak by replacing the bare 'return err' with a goto to the existing error cleanup label, which will drop the reference safely.