PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72496 Linux CVE debrief

The Linux kernel vulnerability (CVE-2026-72496) was resolved with a proper rollback for ioremap failure in the RDMA/bnxt_re module. The bnxt_qplib_alloc_dpi function returned success even if ioremap failed. This change impacts Linux kernel users and administrators who should verify updates for the RDMA/bnxt_re module. The vulnerability affects Linux kernel deployments using the RDMA/bnxt_re module. The proper rollback and -ENOMEM status return enhance the security and reliability of the Linux kernel. Linux kernel users and administrators should review compensating controls for exposed systems and monitor security advisories. Evidence is limited to public CVE details and NVD information. The CVE record was published on 2026-08-15T06:22:23.940Z and has not been modified since then.

Vendor
Linux
Product
Unknown
CVSS
CRITICAL 9.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-09-21
Advisory published
2026-08-15
Advisory updated
2026-09-21

Who should care

Linux kernel users and administrators who use RDMA/bnxt_re module should verify Linux kernel updates and monitor security advisories. They should review compensating controls for exposed systems and check relevant monitoring, detection, and logs for exposed assets. Security teams should track exceptions, retest remediated assets, and confirm affected product deployments in managed environments.

Technical summary

The Linux kernel vulnerability (CVE-2026-72496) was resolved with a proper rollback for ioremap failure in the RDMA/bnxt_re module. The bnxt_qplib_alloc_dpi function returned success even if ioremap failed. The patch adds a proper rollback when ioremap fails and returns -ENOMEM status. This change impacts Linux kernel users and administrators who should verify updates for the RDMA/bnxt_re module and monitor Linux kernel security advisories. The vulnerability affects Linux kernel deployments using the RDMA/bnxt_re module. The proper rollback enhances the security and reliability of the Linux kernel. Linux kernel users and administrators should review compensating controls for exposed systems and check relevant monitoring, detection, and logs for exposed assets.

Defensive priority

Verify Linux kernel updates for RDMA/bnxt_re module.

Recommended defensive actions

  • Verify Linux kernel updates for RDMA/bnxt_re module
  • Monitor Linux kernel security advisories
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions, retest remediated assets
  • Confirm whether affected product deployments exist in managed environments
  • Review the supplied official advisory or CVE record

Evidence notes

The Linux kernel vulnerability (CVE-2026-72496) was resolved with a proper rollback for ioremap failure in the RDMA/bnxt_re module. The bnxt_qplib_alloc_dpi function returned success even if ioremap failed. To verify, defenders should check Linux kernel updates for RDMA/bnxt_re module and monitor Linux kernel security advisories. Evidence is limited to public CVE details and NVD information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72496 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72496

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72496 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72496

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/303f6fef95df5e5316970746d861cf6daeeca77f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/87267803a8c824616eb147c5dad7030a5db6f878

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.