Description
In the Linux kernel, the following vulnerability has been resolved:

net: macb: drop in-flight Tx SKBs on close

The MACB driver has since forever leaked the outgoing SKBs that
have not yet been marked as completed. They live in queue->tx_skb
which gets freed without remorse nor checking.

macb_free_consistent() gets called in a few codepaths, but only close will
trigger the added expressions. In macb_open() and macb_alloc_consistent()
failure cases, queues' tx_skb just got allocated and are empty.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MACB driver in the Linux kernel contains a flaw where it frees pending transmission buffers (SKBs) without verifying their completion status when the driver is closed. This results in kernel memory corruption that can destabilize the system or potentially allow an attacker to execute arbitrary code if the corruption is successfully leveraged.

Affected Systems

All Linux kernel releases that load the macb driver are affected, as the vulnerability stems from the generic MACB network driver. The specific kernel versions are not enumerated in the provided data, so any kernel supporting the macb driver before the applied patch is at risk. The MACB driver is used primarily in embedded systems that include the Linux kernel module for Media Access Control Bus support.

Risk and Exploitability

The CVSS score is 5.5, indicating a moderate risk. The EPSS indicates a less than 1% exploitation probability, and the vulnerability is not listed in CISA's KEV catalogue. The flaw requires the driver to be closed or the module unloaded while transmission queues remain populated—an operation typically performed by a user with root privileges. Therefore the attack vector is likely local privilege escalation and the risk of compromise is low, but the failure can cause kernel crashes or system instability.

Generated by OpenCVE AI on August 18, 2026 at 04:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix for the MACB driver memory corruption issue.
  • If a kernel update is not immediately possible, unload or disable the macb kernel module to prevent the faulty deallocation path from being executed.
  • For systems that require the macb module and cannot be updated, monitor kernel logs for errors or signs of memory corruption and be prepared to upgrade when a patch is made available.

Generated by OpenCVE AI on August 18, 2026 at 04:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4745-1 linux-6.12 security update
History

Sun, 23 Aug 2026 13:15:00 +0000


Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: macb: drop in-flight Tx SKBs on close The MACB driver has since forever leaked the outgoing SKBs that have not yet been marked as completed. They live in queue->tx_skb which gets freed without remorse nor checking. macb_free_consistent() gets called in a few codepaths, but only close will trigger the added expressions. In macb_open() and macb_alloc_consistent() failure cases, queues' tx_skb just got allocated and are empty.
Title net: macb: drop in-flight Tx SKBs on close
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-23T12:46:26.593Z

Reserved: 2026-08-09T03:40:39.900Z

Link: CVE-2026-72017

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:00.550

Modified: 2026-08-23T13:16:37.357

Link: CVE-2026-72017

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72017 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T04:15:04Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime