PatchSiren cyber security CVE debrief
CVE-2026-72342 Linux CVE debrief
A race condition vulnerability was found in the Linux kernel's net/mlx5e module, specifically in the HV VHCA stats agent registration. The vulnerability occurs when the mlx5e_hv_vhca_stats_create() function registers the stats agent through mlx5_hv_vhca_agent_create(), which publishes the agent and schedules an asynchronous control invalidation. However, the delayed_work and priv->stats_agent.agent are only initialized after mlx5_hv_vhca_agent_create() returns, leading to potential crashes or corruption.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers, administrators, and security teams should care about this vulnerability as it affects the net/mlx5e module and could lead to potential crashes or corruption if not addressed. Those responsible for maintaining and securing Linux kernel-based systems need to be aware of this issue to ensure timely mitigation and minimize potential risks. This includes reviewing and applying patches, monitoring system integrity, and assessing the impact on their specific deployments. Additionally, vulnerability management and security teams should prioritize this issue due to its potential impact on system stability and security posture. They should also consider compensating controls and monitor for potential exploitation attempts while remediation is in progress. Affected product operators and platform administrators must also be informed to take necessary actions. The vulnerability's impact on various Linux distributions and the availability of patches or mitigations should also be considered when determining who should care and how they should respond. This involves understanding the vulnerability's technical details, its potential impact on different systems, and the recommended actions for mitigation. Therefore, a broad range of stakeholders, including developers, administrators, and security professionals, should be informed and involved in the response to this vulnerability. This will ensure that all necessary steps are taken to mitigate the vulnerability and minimize potential risks to the systems and data involved. The involvement of these stakeholders is crucial for effective vulnerability management and ensuring the security and stability of Linux kernel-based systems. By being aware of this vulnerability and taking appropriate actions, they can help prevent potential crashes or corruption and maintain the integrity and security of their systems. This includes staying informed about the latest developments, applying patches or mitigations, and monitoring system performance to detect any potential issues. Overall, a coordinated and informed approach is essential for effectively managing this vulnerability and minimizing its impact on Linux kernel
Technical summary
The vulnerability occurs in the net/mlx5e module of the Linux kernel, specifically in the HV VHCA stats agent registration. The mlx5e_hv_vhca_stats_create() function registers the stats agent through mlx5_hv_vhca_agent_create(), which publishes the agent and schedules an asynchronous control invalidation. However, the delayed_work and priv->stats_agent.agent are only initialized after mlx5_hv_vhca_agent_create() returns, leading to potential crashes or corruption.
Defensive priority
High
Recommended defensive actions
- Apply the kernel patch to fix the vulnerability
- Review and update the Linux kernel to the latest version
- Monitor the system for potential crashes or corruption
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability was resolved by initializing priv->stats_agent.work before invoking mlx5_hv_vhca_agent_create() and adding a struct mlx5_hv_vhca_agent **ctx_update out-parameter to mlx5_hv_vhca_agent_create().
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72342 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72342
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72342 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72342
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/24c77044cdfcf5b8b2e9f3b620d8b9aa392d9add
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/60fddda7207d81fea71463abd403f0b10f74f2e1
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/89b25b5f46f488ea3b29b3444864c76944c9075b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b0fd6d3bb06182f19f3b59a53f57b5098b99048a
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e8fc3304cb67fb1d7d11ff9ef9abd5fb64e7e1d5
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/f5677797b094c3ec5fb350eb8ea7710b88a3d018
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.