In the Linux kernel, the following vulnerability has been resolved: net: liquidio: fix BAR resource leak on PF number failure If cn23xx_get_pf_num()… (CVE-2026-72038)
A resource leak vulnerability in the Linux kernel's liquidio network driver was fixed. The issue occurs when the function cn23xx_get_pf_num() fails, causing the function to return without unmapping BAR resources properly. This could lead to resource leaks in the kernel.
AI Analysis
Technical Summary
The Linux kernel liquidio network driver contained a vulnerability where, upon failure of the cn23xx_get_pf_num() function, the code path returned without unmapping either Base Address Register (BAR) resource. This improper handling results in a resource leak. The fix ensures that both BARs are unmapped before returning from the error path, preventing the leak. The vulnerability was identified through manual code review.
Potential Impact
The vulnerability causes a resource leak in the kernel's liquidio driver when a specific function fails. While this does not directly indicate code execution or privilege escalation, resource leaks can degrade system stability or lead to denial of service over time if exploited.
Mitigation Recommendations
A fix has been applied to the Linux kernel to unmap BAR resources properly on failure of cn23xx_get_pf_num(). Users should update to a kernel version that includes this fix. No additional mitigation is indicated.
In the Linux kernel, the following vulnerability has been resolved: net: liquidio: fix BAR resource leak on PF number failure If cn23xx_get_pf_num()… (CVE-2026-72038)
Description
A resource leak vulnerability in the Linux kernel's liquidio network driver was fixed. The issue occurs when the function cn23xx_get_pf_num() fails, causing the function to return without unmapping BAR resources properly. This could lead to resource leaks in the kernel.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel liquidio network driver contained a vulnerability where, upon failure of the cn23xx_get_pf_num() function, the code path returned without unmapping either Base Address Register (BAR) resource. This improper handling results in a resource leak. The fix ensures that both BARs are unmapped before returning from the error path, preventing the leak. The vulnerability was identified through manual code review.
Potential Impact
The vulnerability causes a resource leak in the kernel's liquidio driver when a specific function fails. While this does not directly indicate code execution or privilege escalation, resource leaks can degrade system stability or lead to denial of service over time if exploited.
Mitigation Recommendations
A fix has been applied to the Linux kernel to unmap BAR resources properly on failure of cn23xx_get_pf_num(). Users should update to a kernel version that includes this fix. No additional mitigation is indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-c536-fgj4-j8c9
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-72038"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a808b78bf8831d539501aa8
Added to database: 08/15/2026, 15:53:28 UTC
Last enriched: 08/15/2026, 17:06:38 UTC
Last updated: 08/15/2026, 17:06:38 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.