CVE-2026-72448

high

Description

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix leak of SQ timestamp buffer on teardown The send-queue timestamp ring is allocated with qmem_alloc() when timestamping is used, but otx2_free_sq_res() never freed sq->timestamps, leaking that memory across ifdown and device removal. Add the missing qmem_free() alongside the other SQ companion buffers.

References

https://git.kernel.org/stable/c/e8e9dff204e8d8553495893e1a44d2b5021648de

https://git.kernel.org/stable/c/e68ada66afcae0bc2a7c06b43c5a9a081d29e7b4

https://git.kernel.org/stable/c/d6c0b0c802d3c49b86cad665a7f3790dc55a0394

https://git.kernel.org/stable/c/c642a530aaaeb9a3e356cedfe77955e7f983380e

https://git.kernel.org/stable/c/a056db30de92945ff8ee6033096678bfbae878e3

https://git.kernel.org/stable/c/452ec5058ea4ed63adae8d6beeac9ee687fe8061

https://git.kernel.org/stable/c/3d45d40b872aec0073d4cf08956a6c9b87c5e396

https://git.kernel.org/stable/c/19d2d36e193c3fb515c052a56bfc83d8ac7b6764

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-17

Risk Information

CVSS v2

Base Score: 6.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00184