CVE-2026-72040: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ipmi: fix refcount leak in i_ipmi_request() When a caller provides a `supplied_recv` message to i_ipmi_request(), the function increments the user's `nr_msgs` reference count. If an error occurs later, the out_err cleanup path only frees the recv_msg if the function allocated it itself (i.e., !supplied_recv). In the supplied_recv case the cleanup is skipped, leaving the reference count elevated. The caller ipmi_request_supply_msgs() does not release the supplied_recv on error, so the reference is permanently leaked. Fix this by explicitly reverting the reference count operations when a supplied recv_msg with a valid user pointer is present in the error path: decrement nr_msgs and drop the user's kref.
Affected products
- Linux Linux: from 6.1.157, before 6.1.184 (fixed in 6.1.184); from 6.6.113, before 6.6.148 (fixed in 6.6.148); from 6.12.54, before 6.12.101 (fixed in 6.12.101); from 6.17.4, before 6.18 (fixed in 6.18); from 6.18, before 6.18.40 (fixed in 6.18.40); from 6.19, before 7.1.5 (fixed in 7.1.5)
Published 2026-08-15. Last modified 2026-08-23.