CVE-2026-72499: Linux
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Free CQ toggle page after firmware teardown Free the toggle page only after firmware teardown completes so that an NQ interrupt arriving during bnxt_qplib_destroy_cq() won't write the toggle value to an already-freed page. Move free_page() after bnxt_qplib_destroy_cq.
Affected products
- Linux Linux: from 6.8, before 7.1.5 (fixed in 7.1.5)
Published 2026-08-15. Last modified 2026-08-17.