CVE-2026-68328: nfp: Check resource mutex allocation
In the Linux kernel, the following vulnerability has been resolved:
nfp: Check resource mutex allocation
nfpcppresourcefind() allocates a CPP mutex handle for the matching resource-table entry and then reports success. nfpresourcetryacquire() immediately passes that handle to nfpcppmutextrylock().
However, nfpcppmutexalloc() returns NULL on failure. If that happens for a matching table entry, the resource lookup still returns success and the following trylock dereferences a NULL mutex pointer while opening the resource.
nfpresourceacquire() already treats failure to allocate the table mutex as -ENOMEM. Do the same for the resource mutex and fail the lookup before publishing the rest of the resource handle.
This issue was found by a static analysis checker and confirmed by manual source review.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68328?
CVE-2026-68328 has a risk rating of 34.
How do I fix CVE-2026-68328?
To fix CVE-2026-68328, update your Linux Kernel to the latest version that includes the patch for this vulnerability.
What systems are affected by CVE-2026-68328?
CVE-2026-68328 affects the Linux Kernel specifically in the nfp resource handling.
What are the potential impacts of CVE-2026-68328?
The potential impacts of CVE-2026-68328 can include resource allocation issues leading to system instability.
When was CVE-2026-68328 published?
CVE-2026-68328 was published on August 10, 2026.