PatchSiren cyber security CVE debrief
CVE-2026-97972 Linux CVE debrief
A memory leak vulnerability was found in the Linux kernel's macb driver. The macb_mii_init() function holds a reference to the 'mdio' child node but only drops it on error paths, leading to a node reference leak on successful probes. This issue can cause memory leaks and potentially lead to denial-of-service or other issues if exploited. Linux kernel developers, administrators, and users of systems relying on the macb driver should assess exposure and apply patches or updates as needed. The CVE record and NVD entry provide details on the vulnerability, but specific affected versions and exploitation details are not provided.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Linux kernel developers, administrators, and users of systems relying on the macb driver should assess exposure and apply patches or updates as needed. The vulnerability can cause memory leaks and potentially lead to denial-of-service or other issues if exploited. Verify Linux kernel versions in use and check for patches or updates addressing CVE-2026-97972. Review system configurations and deployments using the macb driver. Monitor for potential memory
Why it matters
CVE-2026-97972 is a memory leak vulnerability in the Linux kernel's macb driver. While specific exploitation details are not provided, verifying and patching affected systems is crucial to prevent potential issues.
- Verify Linux kernel versions and configurations to identify potential exposure
- Monitor system behavior for signs of memory leaks or unusual activity
- Apply patches or updates to affected systems to prevent potential issues
Technical summary
The Linux kernel's macb driver has a memory leak vulnerability due to a held reference to the 'mdio' child node not being dropped on successful probes. This issue has been resolved in later kernel versions. The vulnerability can cause memory leaks and potentially lead to denial-of-service or other issues if exploited. Linux kernel developers, administrators, and users of systems relying on the macb driver should assess exposure and apply patches or updates as needed. The CVE record and NVD entry provide details on the vulnerability, but specific affected versions and exploitation details are not provided.
Defensive priority
Verify and apply patches for Linux kernel versions affected by CVE-2026-97972, particularly in environments using the macb driver.
Recommended defensive actions
- Verify Linux kernel versions in use and check for patches or updates addressing CVE-2026-97972
- Review system configurations and deployments using the macb driver
- Monitor for potential memory leaks or unusual behavior in affected systems
- Apply patches or updates to affected systems to prevent potential issues
- Verify and apply patches for Linux kernel versions affected by CVE-2026-97972, particularly in environments using the macb driver
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but specific affected versions and exploitation details are not provided. The vulnerability has been resolved in later kernel versions. Linux kernel developers, administrators, and users of systems relying on the macb driver should assess exposure and apply patches or updates as needed. The memory leak vulnerability can cause memory leaks and potentially lead to denial-of-service or other issues if exploited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97972 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97972
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97972 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97972
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/382a373d9ea7a6ac4de9c022385b6217f65ae3cc
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5fba30080d298edb742396073372385c961578d3
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7d60dc7ff85b73a2119d582ca2d4456b30960380
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.