Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-72339

qede: fix off-by-one in BD ring consumption on build_skb failure
Back to all
CVE

CVE-2026-72339

qede: fix off-by-one in BD ring consumption on build_skb failure

In the Linux kernel, the following vulnerability has been resolved:

qede: fix off-by-one in BD ring consumption on build_skb failure

qederxbuildskb() and qedetparxbuild_skb() do not check for a

NULL return from qedebuildskb(). When it returns NULL under memory

pressure, the functions still consume a BD from the ring before

returning NULL. The callers then recycle additional BDs, resulting in

one extra BD being consumed (off-by-one). This desynchronizes the BD

ring, which can corrupt DMA page reference counts and lead to SLUB

freelist corruption.

Commit 4e910dbe3650 ("qede: confirm skb is allocated before using")

added a NULL check inside qedebuildskb() to prevent a NULL pointer

dereference, but did not address the missing NULL checks in the

callers, making this off-by-one reachable.

Fix this by adding NULL checks for the return value of

qedebuildskb() in both qederxbuild_skb() and

qedetparxbuildskb(), returning NULL immediately before any BD ring

manipulation.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/07be8b8adf91b7ada4c3dacce064d572a6066421, https://git.kernel.org/stable/c/0bf78df2d3ecb1f4964ff42a7327d25845955153, https://git.kernel.org/stable/c/1624aa100c0b218181aa74e3696a389b509298cb, https://git.kernel.org/stable/c/814a5edac8c9fc04051808d5faaa93768e989281, https://git.kernel.org/stable/c/982d6d6bc059c5dff37a2201c2f08c14bcfcbd20, https://git.kernel.org/stable/c/a0a558ca7e75b49e71f8c545c30e8c005e6e4e2f, https://git.kernel.org/stable/c/b066420e57f3402a52c998678b4678252ac9bb63, https://git.kernel.org/stable/c/ecc05d4b20220a09c9c69584fc46ca55248a374a, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72339.json, https://nvd.nist.gov/vuln/detail/CVE-2026-72339, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00745%
EPSS Percentile
0.52114%
Introduced Version
8a8633978b842c88fbcfe00d4e5dde96048f630e,4.18.0,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
a0a558ca7e75b49e71f8c545c30e8c005e6e4e2f,5.10.261,5.15.212,6.1.178,6.6.145,6.12.97,6.18.40,7.1.5,6.1.180-1,5.10.262-1,6.12.100-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading