7.8
HIGH CVSS 3.1
CVE-2026-72072
net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete When an offloaded MACsec RX SC is deleted, macsec_del_rxsc_ctx() freed the per-SC metadata_dst with metadata_dst_free(), which kfree()s the object unconditionally and ignores the dst reference count. The RX datapath in mlx5e_macsec_offload_handle_rx_skb() looks up the SC under rcu_read_lock() via xa_load(), takes a reference with dst_hold() and attaches the dst to the skb with skb_dst_set(). A reader that already obtained the rx_sc pointer can race with the delete path and operate on freed memory. Fix the owner side by dropping the reference with dst_release() instead of freeing unconditionally, and convert the RX datapath to dst_hold_safe() so a reader racing the SC delete cannot attach a dst whose last reference was just dropped; only attach it when a reference was actually taken. mlx5e_macsec_add_rxsc() also published sc_xarray_element via xa_alloc() before rx_sc->md_dst was allocated and initialised, so a datapath reader that looked the SC up by fs_id could observe rx_sc with md_dst still NULL or, on weakly-ordered architectures, a non-NULL md_dst pointer whose contents were not yet visible. NULL-check the xa_load() result and md_dst on the datapath, and reorder add_rxsc() so the xa_alloc() publish happens only after md_dst is fully initialised; the xarray RCU publish then pairs with the rcu_read_lock()/xa_load() in the datapath. Note: macsec_del_rxsc_ctx() also kfree()s rx_sc->sc_xarray_element without an RCU grace period while the same datapath reads it under rcu_read_lock(); that is a separate pre-existing issue left to a follow-up patch. Found by 0sec automated security-research tooling (https://0sec.ai).

INFO

Published Date :

Aug. 15, 2026, 6:21 a.m.

Last Modified :

Aug. 17, 2026, 6:18 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-72072 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
Fix a use-after-free in MACsec RX SC deletion by managing metadata_dst references properly.
  • Drop reference using dst_release instead of unconditional free.
  • Use dst_hold_safe in RX datapath for SC delete race.
  • Null-check xa_load result and md_dst in datapath.
  • Reorder add_rxsc to initialize md_dst before publishing.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-72072 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-72072 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-72072 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-72072 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': 'b1a4d0c568bbb52c7c04f4fce3c097dae89ed6cb', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': '218cc15a4c907659ad4b0e68c535c61594311205', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': '4a5073b7b30243658f58b2d2d35a823da7fd34d9', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': 'ed3cc4218070d6b98bf5fb456dccae424fd38c4f', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': '088873af13590ebde10de2ade847f57a05ec61c6', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': 'de74d8fd10291763d97b218f09adcc7513c975e4', 'versionType': 'git'}], 'programFiles': ['drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.1'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.1', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': 'b1a4d0c568bbb52c7c04f4fce3c097dae89ed6cb', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': '218cc15a4c907659ad4b0e68c535c61594311205', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': '4a5073b7b30243658f58b2d2d35a823da7fd34d9', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': 'ed3cc4218070d6b98bf5fb456dccae424fd38c4f', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': '088873af13590ebde10de2ade847f57a05ec61c6', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': 'de74d8fd10291763d97b218f09adcc7513c975e4', 'versionType': 'git'}], 'programFiles': ['drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.1'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.1', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c'], 'defaultStatus': 'affected'}]
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 15, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': 'b1a4d0c568bbb52c7c04f4fce3c097dae89ed6cb', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': '218cc15a4c907659ad4b0e68c535c61594311205', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': '4a5073b7b30243658f58b2d2d35a823da7fd34d9', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': 'ed3cc4218070d6b98bf5fb456dccae424fd38c4f', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': '088873af13590ebde10de2ade847f57a05ec61c6', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7c9400cbc48c3713190b3bce4e0c87e924e4104', 'lessThan': 'de74d8fd10291763d97b218f09adcc7513c975e4', 'versionType': 'git'}], 'programFiles': ['drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.1'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.1', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete When an offloaded MACsec RX SC is deleted, macsec_del_rxsc_ctx() freed the per-SC metadata_dst with metadata_dst_free(), which kfree()s the object unconditionally and ignores the dst reference count. The RX datapath in mlx5e_macsec_offload_handle_rx_skb() looks up the SC under rcu_read_lock() via xa_load(), takes a reference with dst_hold() and attaches the dst to the skb with skb_dst_set(). A reader that already obtained the rx_sc pointer can race with the delete path and operate on freed memory. Fix the owner side by dropping the reference with dst_release() instead of freeing unconditionally, and convert the RX datapath to dst_hold_safe() so a reader racing the SC delete cannot attach a dst whose last reference was just dropped; only attach it when a reference was actually taken. mlx5e_macsec_add_rxsc() also published sc_xarray_element via xa_alloc() before rx_sc->md_dst was allocated and initialised, so a datapath reader that looked the SC up by fs_id could observe rx_sc with md_dst still NULL or, on weakly-ordered architectures, a non-NULL md_dst pointer whose contents were not yet visible. NULL-check the xa_load() result and md_dst on the datapath, and reorder add_rxsc() so the xa_alloc() publish happens only after md_dst is fully initialised; the xarray RCU publish then pairs with the rcu_read_lock()/xa_load() in the datapath. Note: macsec_del_rxsc_ctx() also kfree()s rx_sc->sc_xarray_element without an RCU grace period while the same datapath reads it under rcu_read_lock(); that is a separate pre-existing issue left to a follow-up patch. Found by 0sec automated security-research tooling (https://0sec.ai).
    Added Reference https://git.kernel.org/stable/c/088873af13590ebde10de2ade847f57a05ec61c6
    Added Reference https://git.kernel.org/stable/c/218cc15a4c907659ad4b0e68c535c61594311205
    Added Reference https://git.kernel.org/stable/c/4a5073b7b30243658f58b2d2d35a823da7fd34d9
    Added Reference https://git.kernel.org/stable/c/b1a4d0c568bbb52c7c04f4fce3c097dae89ed6cb
    Added Reference https://git.kernel.org/stable/c/de74d8fd10291763d97b218f09adcc7513c975e4
    Added Reference https://git.kernel.org/stable/c/ed3cc4218070d6b98bf5fb456dccae424fd38c4f
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.