Description
In the Linux kernel, the following vulnerability has been resolved:

net: macb: drop in-flight Tx SKBs on close

The MACB driver has since forever leaked the outgoing SKBs that
have not yet been marked as completed. They live in queue->tx_skb
which gets freed without remorse nor checking.

macb_free_consistent() gets called in a few codepaths, but only close will
trigger the added expressions. In macb_open() and macb_alloc_consistent()
failure cases, queues' tx_skb just got allocated and are empty.
Published: 2026-08-15
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MACB driver in the Linux kernel contains a flaw where it frees pending transmission buffers (SKBs) without verifying their completion status when the driver is closed. This results in kernel memory corruption that can destabilize the system or potentially allow an attacker to execute arbitrary code if the corruption is successfully leveraged.

Affected Systems

All Linux kernel releases that load the macb driver are affected, as the vulnerability stems from the generic MACB network driver. The specific kernel versions are not enumerated in the provided data, so any kernel supporting the macb driver before the applied patch is at risk. The MACB driver is used primarily in embedded systems that include the Linux kernel module for Media Access Control Bus support.

Risk and Exploitability

The CVSS score is not published, but the EPSS indicates a less than 1% exploitation probability, and the vulnerability is not listed in CISA's KEV catalogue. The flaw requires the driver to be closed or the module unloaded while transmission queues remain populated—an operation typically performed by a user with root privileges. Therefore the attack vector is likely local privilege escalation and the risk of compromise is low, but the failure can cause kernel crashes or system instability.

Generated by OpenCVE AI on August 15, 2026 at 21:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix for the MACB driver memory corruption issue.
  • If a kernel update is not immediately possible, unload or disable the macb kernel module to prevent the faulty deallocation path from being executed.
  • For systems that require the macb module and cannot be updated, monitor kernel logs for errors or signs of memory corruption and be prepared to upgrade when a patch is made available.

Generated by OpenCVE AI on August 15, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: macb: drop in-flight Tx SKBs on close The MACB driver has since forever leaked the outgoing SKBs that have not yet been marked as completed. They live in queue->tx_skb which gets freed without remorse nor checking. macb_free_consistent() gets called in a few codepaths, but only close will trigger the added expressions. In macb_open() and macb_alloc_consistent() failure cases, queues' tx_skb just got allocated and are empty.
Title net: macb: drop in-flight Tx SKBs on close
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:51:44.698Z

Reserved: 2026-08-09T03:40:39.900Z

Link: CVE-2026-72017

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:00.550

Modified: 2026-08-15T06:21:00.550

Link: CVE-2026-72017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T13:00:05Z

Weaknesses

No weakness.