CVE-2026-72042: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix user refcount underflow in event delivery ipmi_alloc_recv_msg(user) takes the temporary user reference owned by the receive message, and ipmi_free_recv_msg() drops it again. If event delivery fails after allocating receive messages for earlier users, handle_read_event_rsp() rolls those messages back with ipmi_free_recv_msg(). That rollback path still drops user->refcount explicitly after freeing each message. The extra put can free a user that remains linked on intf->users, so later event delivery may dereference a freed user or trip refcount_t's addition-on-zero warning when ipmi_alloc_recv_msg() tries to acquire another reference. Remove the stale explicit put and the now-dead user assignment. Keep the list_del() and ipmi_free_recv_msg() calls; they are the required rollback operations.
Affected products
- Linux Linux: from 6.1.157, before 6.2 (fixed in 6.2); from 6.6.113, before 6.7 (fixed in 6.7); from 6.12.54, before 6.13 (fixed in 6.13); from 6.17.4, before 6.18 (fixed in 6.18); from 6.18, before 6.18.40 (fixed in 6.18.40); from 6.19, before 7.1.5 (fixed in 7.1.5)
Published 2026-08-15. Last modified 2026-08-17.