CVE-2026-68375

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Handle partially initialized auxiliary devices bnxt_aux_devices_init() calls auxiliary_device_init() before all fields used by bnxt_aux_dev_release() are initialized. After auxiliary_device_init() succeeds, later errors must unwind with auxiliary_device_uninit(), which invokes the release callback. The release callback assumes that aux_priv->id, aux_priv->edev, edev->net and edev->ulp_tbl are all populated. If allocation fails after auxiliary_device_init(), the release path can otherwise dereference or clear partially initialized state. Allocate and attach the bnxt_en_dev and ULP table before calling auxiliary_device_init(), so the release callback only sees a fully initialized auxiliary private object. If auxiliary_device_init() itself fails, free those allocations directly because device_initialize() has not run and the release callback will not be invoked. This issue was found by a static analysis checker and confirmed by manual source review.

Package Linux Kernel
Published 2026-08-10
Last modified 2026-08-17
Patch available
Yes

Affected versions

Linux kernel versions 6.10 and later are affected. Fixed in 7.1.6, 7.2 and their respective stable series.

Affected from
≥ 6.10
Fixed in
✓ 7.1.6 7.1.x ✓ 7.2

Frequently asked questions

  • What is CVE-2026-68375?

    CVE-2026-68375 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.10 onward and has been patched in 7.1.6 and 7.2. CVE-2026-68375 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-68375?

    Yes. CVE-2026-68375 has been patched. Fixed versions include 7.1.6 and 7.2. If you are running Linux kernel 6.10 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-68375 actively exploited?

    No. CVE-2026-68375 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.