Junglewise Threat Intelligence

CVE-2026-72411: Linux kernel mxl862xx use-after-free in CRC error handler

CVE-2026-72411 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The mxl862xx network driver in the Linux kernel can experience a race condition where a CRC error handler attempts to access network port data that has already been freed during device shutdown. This can cause the system to crash or potentially execute arbitrary code if exploited. Devices using the mxl862xx driver (used in network switches) are vulnerable if they experience MDIO communication errors while being removed.

Technical details

The vulnerability is a use-after-free (CWE-416) in the mxl862xx_crc_err_work_fn() function within the Linux kernel's DSA (Distributed Switch Architecture) driver. The root cause is a race condition: when an MDIO CRC error occurs, the error handler walks and closes DSA port objects; however, mxl862xx_remove() calls dsa_unregister_switch() before cancelling this work, which frees the port structures. If a CRC error is scheduled during teardown, the work handler can dereference freed memory. The fix guards the port walk with a MXL862XX_FLAG_WORK_STOPPED flag that is checked under rtnl_lock(), ensuring the work either completes before teardown sees valid ports or skips execution after unregistration. The vulnerability affects network drivers and requires local or adjacent network access to trigger via MDIO errors.

Affected products

  • Linux Linux kernel all versions containing the mxl862xx driver with the vulnerable CRC error handling code

Timeline

  • 2026-08-15: disclosed: Published as CVE-2026-72411
  • 2026-06-24: patched: Upstream patch committed by Jakub Kicinski
  • 2026-07-24: patched: Backported to stable kernel branches

References

Related threats