CVE-2026-63972: Linux Kernel
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net: mana: Skip redundant detach on already-detached port When mana_per_port_queue_reset_work_handler() runs after a previous detach succeeded but attach failed, the port is left in a detached state with apc->tx_qp and apc->rxqs already freed. Calling mana_detach() again unconditionally leads to NULL pointer dereferences during queue teardown. Add an early exit in mana_detach() when the port is already in detached state (!netif_device_present) for non-close callers, making it safe to call idempotently. This allows the queue reset handler and other recovery paths to simply retry mana_attach() without redundant teardown.
Affected products
- Linux Linux Kernel: from 6.18.33, before 6.18.35 (fixed in 6.18.35); from 7.0, before 7.0.12 (fixed in 7.0.12); version 7.1 only
Published 2026-07-19. Last modified 2026-10-02.