VYPR
High severity7.5NVD Advisory· Published Jul 19, 2026· Updated Jul 30, 2026

CVE-2026-63972

CVE-2026-63972

Description

In the Linux kernel, the following vulnerability has been resolved:

net: mana: Skip redundant detach on already-detached port

When mana_per_port_queue_reset_work_handler() runs after a previous detach succeeded but attach failed, the port is left in a detached state with apc->tx_qp and apc->rxqs already freed. Calling mana_detach() again unconditionally leads to NULL pointer dereferences during queue teardown.

Add an early exit in mana_detach() when the port is already in detached state (!netif_device_present) for non-close callers, making it safe to call idempotently. This allows the queue reset handler and other recovery paths to simply retry mana_attach() without redundant teardown.

Affected products

15

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.