Junglewise Threat Intelligence

CVE-2026-72042: Linux kernel IPMI user refcount underflow in event delivery

CVE-2026-72042 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's IPMI (Intelligent Platform Management Interface) subsystem contains a reference-counting bug in event delivery that can cause a use-after-free condition. When event delivery fails partway through, the rollback logic incorrectly double-frees user objects, allowing attackers to trigger a kernel panic or potentially execute code with kernel privileges on systems with IPMI enabled.

Technical details

The vulnerability is a use-after-free caused by double reference-count decrement in the IPMI message handler. When handle_read_event_rsp() allocates receive messages for multiple users and an allocation fails mid-way, the rollback path calls ipmi_free_recv_msg() (which correctly drops the temporary user reference) but then executes a stale explicit kref_put() on the same user object. This extra put can free a user object that remains linked in intf->users, leading to a freed object dereference on subsequent event delivery or triggering refcount_t's warning on addition-to-zero. The fix removes the redundant explicit put and user assignment while preserving correct list_del() and ipmi_free_recv_msg() calls. No authentication or network access is required; local code execution or kernel panic can occur during normal IPMI event handling.

Affected products

  • Linux Linux kernel v6.18 and later

Timeline

  • 2026-08-15: disclosed
  • 2026-05-21: patched: Fix committed upstream (6aa9e61c46465d231e9beddf56af7effd71be682)

References

Related threats