Description
In the Linux kernel, the following vulnerability has been resolved:

net: sparx5: unregister blocking notifier on init failure

sparx5_register_notifier_blocks() registers the switchdev blocking
notifier before allocating the ordered workqueue. If the workqueue
allocation fails, the error path unregisters the switchdev and netdevice
notifiers, but leaves the blocking notifier registered.

Add a separate error label for the workqueue allocation failure path and
unregister the switchdev blocking notifier there.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel vulnerability is located in the sparx5 switchdev module. During initialization, sparx5_register_notifier_blocks registers a blocking notifier before allocating the ordered workqueue. If the workqueue allocation fails, the error path unregisters the switchdev and netdevice notifiers but leaves the blocking notifier registered. This omission can leave a dangling notifier that may be invoked by later code paths, producing undefined behavior or instability. The flaw is a resource management error.

Affected Systems

Linux kernel distributions that include the sparx5 switchdev implementation are affected. The CPE entry indicates the entire Linux kernel family. No specific versions or patch levels are listed in the provided data.

Risk and Exploitability

The CVSS score of 7.8 and an EPSS score of <1% suggest moderate to high severity but a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog and no public exploit has been documented. The flaw is triggered by an internal failure during kernel initialization – specifically, the failure of ordered workqueue allocation – so the attack vector is inferred to be internal boot or module load failure rather than an externally observable attack.

Generated by OpenCVE AI on August 18, 2026 at 05:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the sparx5 notifier unregistration fix.
  • If an updated kernel is not yet available, apply the relevant commit (e.g., 17f113e7b622dc850992ade540181717de6a8561) directly to the source tree and rebuild the kernel.
  • If a patch cannot be applied immediately, consider disabling or reconfiguring switchdev functionality to avoid the code path that registers the problematic notifier.

Generated by OpenCVE AI on August 18, 2026 at 05:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: sparx5: unregister blocking notifier on init failure sparx5_register_notifier_blocks() registers the switchdev blocking notifier before allocating the ordered workqueue. If the workqueue allocation fails, the error path unregisters the switchdev and netdevice notifiers, but leaves the blocking notifier registered. Add a separate error label for the workqueue allocation failure path and unregister the switchdev blocking notifier there.
Title net: sparx5: unregister blocking notifier on init failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:40:22.667Z

Reserved: 2026-08-09T03:40:39.906Z

Link: CVE-2026-72109

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:25.203

Modified: 2026-08-17T06:18:10.020

Link: CVE-2026-72109

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72109 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T05:45:03Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime