{"id":"CVE-2026-72339","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-72339","summary":"qede: fix off-by-one in BD ring consumption on build_skb failure","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nqede: fix off-by-one in BD ring consumption on build_skb failure\n\nqede_rx_build_skb() and qede_tpa_rx_build_skb() do not check for a\nNULL return from qede_build_skb(). When it returns NULL under memory\npressure, the functions still consume a BD from the ring before\nreturning NULL. The callers then recycle additional BDs, resulting in\none extra BD being consumed (off-by-one). This desynchronizes the BD\nring, which can corrupt DMA page reference counts and lead to SLUB\nfreelist corruption.\n\nCommit 4e910dbe3650 (\"qede: confirm skb is allocated before using\")\nadded a NULL check inside qede_build_skb() to prevent a NULL pointer\ndereference, but did not address the missing NULL checks in the\ncallers, making this off-by-one reachable.\n\nFix this by adding NULL checks for the return value of\nqede_build_skb() in both qede_rx_build_skb() and\nqede_tpa_rx_build_skb(), returning NULL immediately before any BD ring\nmanipulation.","published":"2026-08-15T05:55:46.480Z","modified":"2026-08-16T03:48:40.328923802Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"5.10.261"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/07be8b8adf91b7ada4c3dacce064d572a6066421"},{"type":"WEB","url":"https://git.kernel.org/stable/c/0bf78df2d3ecb1f4964ff42a7327d25845955153"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1624aa100c0b218181aa74e3696a389b509298cb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/814a5edac8c9fc04051808d5faaa93768e989281"},{"type":"WEB","url":"https://git.kernel.org/stable/c/982d6d6bc059c5dff37a2201c2f08c14bcfcbd20"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a0a558ca7e75b49e71f8c545c30e8c005e6e4e2f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b066420e57f3402a52c998678b4678252ac9bb63"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ecc05d4b20220a09c9c69584fc46ca55248a374a"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72339.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72339"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-16T03:48:40.328923802Z"}}