{"id":"CVE-2026-72339","summary":"qede: fix off-by-one in BD ring consumption on build_skb failure","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nqede: fix off-by-one in BD ring consumption on build_skb failure\n\nqede_rx_build_skb() and qede_tpa_rx_build_skb() do not check for a\nNULL return from qede_build_skb(). When it returns NULL under memory\npressure, the functions still consume a BD from the ring before\nreturning NULL. The callers then recycle additional BDs, resulting in\none extra BD being consumed (off-by-one). This desynchronizes the BD\nring, which can corrupt DMA page reference counts and lead to SLUB\nfreelist corruption.\n\nCommit 4e910dbe3650 (\"qede: confirm skb is allocated before using\")\nadded a NULL check inside qede_build_skb() to prevent a NULL pointer\ndereference, but did not address the missing NULL checks in the\ncallers, making this off-by-one reachable.\n\nFix this by adding NULL checks for the return value of\nqede_build_skb() in both qede_rx_build_skb() and\nqede_tpa_rx_build_skb(), returning NULL immediately before any BD ring\nmanipulation.","modified":"2026-08-18T04:17:29.316179302Z","published":"2026-08-15T05:55:46.480Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72339.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/07be8b8adf91b7ada4c3dacce064d572a6066421"},{"type":"WEB","url":"https://git.kernel.org/stable/c/0bf78df2d3ecb1f4964ff42a7327d25845955153"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1624aa100c0b218181aa74e3696a389b509298cb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/814a5edac8c9fc04051808d5faaa93768e989281"},{"type":"WEB","url":"https://git.kernel.org/stable/c/982d6d6bc059c5dff37a2201c2f08c14bcfcbd20"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a0a558ca7e75b49e71f8c545c30e8c005e6e4e2f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b066420e57f3402a52c998678b4678252ac9bb63"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ecc05d4b20220a09c9c69584fc46ca55248a374a"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72339.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72339"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"8a8633978b842c88fbcfe00d4e5dde96048f630e"},{"fixed":"ecc05d4b20220a09c9c69584fc46ca55248a374a"},{"fixed":"07be8b8adf91b7ada4c3dacce064d572a6066421"},{"fixed":"1624aa100c0b218181aa74e3696a389b509298cb"},{"fixed":"0bf78df2d3ecb1f4964ff42a7327d25845955153"},{"fixed":"814a5edac8c9fc04051808d5faaa93768e989281"},{"fixed":"b066420e57f3402a52c998678b4678252ac9bb63"},{"fixed":"982d6d6bc059c5dff37a2201c2f08c14bcfcbd20"},{"fixed":"a0a558ca7e75b49e71f8c545c30e8c005e6e4e2f"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-72339.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.18.0"},{"fixed":"5.10.261"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.212"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.97"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.40"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-72339.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}