๐Ÿ” CVE Alert

CVE-2026-72339

UNKNOWN 0.0

qede: fix off-by-one in BD ring consumption on build_skb failure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: qede: fix off-by-one in BD ring consumption on build_skb failure qede_rx_build_skb() and qede_tpa_rx_build_skb() do not check for a NULL return from qede_build_skb(). When it returns NULL under memory pressure, the functions still consume a BD from the ring before returning NULL. The callers then recycle additional BDs, resulting in one extra BD being consumed (off-by-one). This desynchronizes the BD ring, which can corrupt DMA page reference counts and lead to SLUB freelist corruption. Commit 4e910dbe3650 ("qede: confirm skb is allocated before using") added a NULL check inside qede_build_skb() to prevent a NULL pointer dereference, but did not address the missing NULL checks in the callers, making this off-by-one reachable. Fix this by adding NULL checks for the return value of qede_build_skb() in both qede_rx_build_skb() and qede_tpa_rx_build_skb(), returning NULL immediately before any BD ring manipulation.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
8a8633978b842c88fbcfe00d4e5dde96048f630e < ecc05d4b20220a09c9c69584fc46ca55248a374a 8a8633978b842c88fbcfe00d4e5dde96048f630e < 07be8b8adf91b7ada4c3dacce064d572a6066421 8a8633978b842c88fbcfe00d4e5dde96048f630e < 1624aa100c0b218181aa74e3696a389b509298cb 8a8633978b842c88fbcfe00d4e5dde96048f630e < 0bf78df2d3ecb1f4964ff42a7327d25845955153 8a8633978b842c88fbcfe00d4e5dde96048f630e < 814a5edac8c9fc04051808d5faaa93768e989281 8a8633978b842c88fbcfe00d4e5dde96048f630e < b066420e57f3402a52c998678b4678252ac9bb63 8a8633978b842c88fbcfe00d4e5dde96048f630e < 982d6d6bc059c5dff37a2201c2f08c14bcfcbd20 8a8633978b842c88fbcfe00d4e5dde96048f630e < a0a558ca7e75b49e71f8c545c30e8c005e6e4e2f
Linux / Linux
4.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ecc05d4b20220a09c9c69584fc46ca55248a374a git.kernel.org: https://git.kernel.org/stable/c/07be8b8adf91b7ada4c3dacce064d572a6066421 git.kernel.org: https://git.kernel.org/stable/c/1624aa100c0b218181aa74e3696a389b509298cb git.kernel.org: https://git.kernel.org/stable/c/0bf78df2d3ecb1f4964ff42a7327d25845955153 git.kernel.org: https://git.kernel.org/stable/c/814a5edac8c9fc04051808d5faaa93768e989281 git.kernel.org: https://git.kernel.org/stable/c/b066420e57f3402a52c998678b4678252ac9bb63 git.kernel.org: https://git.kernel.org/stable/c/982d6d6bc059c5dff37a2201c2f08c14bcfcbd20 git.kernel.org: https://git.kernel.org/stable/c/a0a558ca7e75b49e71f8c545c30e8c005e6e4e2f