Executive brief
The sungem ethernet driver in the Linux kernel contains a double-free vulnerability in its device initialization error path. When network device registration fails during driver probe, the cleanup code frees memory and resources twice, which can cause kernel memory corruption or system crash. This affects systems using Sun GEM ethernet adapters when probe fails.
Technical details
The vulnerability is a double-free error in the gem_init_one() probe function. When register_netdev() fails, gem_init_one() calls gem_remove_one() to clean up, but gem_remove_one() already frees the DMA blocks, MMIO mappings, PCI regions, and net_device structure. The function then continues through its own error handling labels and attempts to free those same resources a second time. The fix introduces a new error label (err_out_clear_drvdata) to clear driver data and remove the NAPI instance while bypassing the redundant gem_remove_one() call, allowing a single-pass cleanup. Attack vector is local; exploitation occurs during device probe failure, which can be triggered by unprivileged code in containerized or virtualized environments that control device enumeration.
Affected products
- Linux Linux Kernel All versions from 2.6.12-rc2 onwards until the patch is applied
Timeline
- 2026-06-23: disclosed: Patch submitted by Ruoyu Wang
- 2026-06-24: patched: Merged into mainline kernel
- 2026-08-15: advisory: CVE-2026-72406 published