Description
In the Linux kernel, the following vulnerability has been resolved:

net: sxgbe: free TX rings on RX allocation failure

When RX descriptor ring allocation fails, init_dma_desc_rings() only
frees the partially allocated RX rings and returns. The TX rings that
were allocated earlier in the same function are leaked.

Rearrange error labels to clean up TX rings upon RX failures.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel’s sxgbe network driver has a defect in the init_dma_desc_rings function. When an RX descriptor ring allocation fails, only the partially allocated RX rings are freed, leaving the previously allocated TX rings unreleased. This results in a kernel memory leak of DMA descriptor rings. If the failure occurs repeatedly, the accumulated leaked memory could exhaust kernel space and force the kernel to handle out‑of‑memory conditions, which would manifest as a crash or reboot of the host. The weakness is a memory leak, which is a form of resource exhaustion. The likely attack vector is the exploitation of a situation where the RX allocation fails, which could be caused by traffic load or by a deliberate resource denial to trigger the failure, though the CVE does not provide an explicit exploit.

Affected Systems

All Linux kernel builds that incorporate the legacy sxgbe driver are potentially affected. Since no specific kernel release list was supplied, any distribution or custom kernel that includes the old driver prior to the patch is considered vulnerable until updated.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% signifies a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog, meaning it has not been observed as a known exploit in the wild. A successful exploitation would require triggering repeated RX allocation failures, which an attacker could do if they can influence the network interface, but no publicly available exploits are documented.

Generated by OpenCVE AI on August 21, 2026 at 23:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the sxgbe driver patch.
  • If an upgrade is not immediately possible, temporarily disable the sxgbe driver or block the affected network interface to prevent the driver from operating.
  • Monitor kernel logs for DMA descriptor allocation failures and track system memory usage for abnormal growth that may indicate a leak.

Generated by OpenCVE AI on August 21, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6466-1 linux security update
History

Fri, 21 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-391
CWE-400

Fri, 21 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Wed, 19 Aug 2026 17:00:00 +0000


Sat, 15 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-391
CWE-400

Sat, 15 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: sxgbe: free TX rings on RX allocation failure When RX descriptor ring allocation fails, init_dma_desc_rings() only frees the partially allocated RX rings and returns. The TX rings that were allocated earlier in the same function are leaked. Rearrange error labels to clean up TX rings upon RX failures.
Title net: sxgbe: free TX rings on RX allocation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-19T16:38:29.844Z

Reserved: 2026-08-15T05:44:03.911Z

Link: CVE-2026-74525

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T13:17:57.763

Modified: 2026-08-19T17:21:09.177

Link: CVE-2026-74525

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74525 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:30:17Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime