Answer in brief
CVE-2026-45891 records a High severity (CVSS 7.8) vulnerability in net: hns3: fix double free issue for tx spare buffer. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-45891 records a High severity (CVSS 7.8) vulnerability in net: hns3: fix double free issue for tx spare buffer. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=907676b130711fd1f627824559e92259db2061d1 <fb6a4c376d454b425555b1b0bda36e99f56ec307 || >=907676b130711fd1f627824559e92259db2061d1 <43015461662d41dcfb3bb95fadd8a2a42ad8eacf || >=907676b130711fd1f627824559e92259db2061d1 <6dc10494cfe27b6f1e9adb7e293293ae39c50b7c || >=907676b130711fd1f627824559e92259db2061d1 <d2c785733dfb853ea0b53984c75662a1af230a94 || >=907676b130711fd1f627824559e92259db2061d1 <fdbccddb7e7822016601829f95de4008e193f7bc || >=907676b130711fd1f627824559e92259db2061d1 <c3659273860bed0c8e573b865e3769abc51225a8 || >=907676b130711fd1f627824559e92259db2061d1 <6d2f142b1e4b203387a92519d9d2e34752a79dbb | fb6a4c376d454b425555b1b0bda36e99f56ec307, 43015461662d41dcfb3bb95fadd8a2a42ad8eacf, 6dc10494cfe27b6f1e9adb7e293293ae39c50b7c, d2c785733dfb853ea0b53984c75662a1af230a94, fdbccddb7e7822016601829f95de4008e193f7bc, c3659273860bed0c8e573b865e3769abc51225a8, 6d2f142b1e4b203387a92519d9d2e34752a79dbb |
| Linux/Linuxgeneric | 5.14 | Not reported |
Published upstream
May 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix double free issue for tx spare buffer In hns3_set_ringparam(), a temporary copy (tmp_rings) of the ring structure is created for rollback. However, the tx_spare pointer in the original ring handle is incorrectly left pointing to the old backup memory. Later, if memory allocation fails in hns3_init_all_ring() during the setup, the error path attempts to free all newly allocated rings. Since tx_spare contains a stale (non-NULL) pointer from the backup, it is mistaken for a newly allocated buffer and is erroneously freed, leading to a double-free of the backup memory. The root cause is that the tx_spare field was not cleared after its value was saved in tmp_rings, leaving a dangling pointer. Fix this by setting tx_spare to NULL in the original ring structure when the creation of the new `tx_spare` fails. This ensures the error cleanup path only frees genuinely newly allocated buffers.
Quoted source text, attributed separately from HOL analysis.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=907676b130711fd1f627824559e92259db2061d1 <fb6a4c376d454b425555b1b0bda36e99f56ec307 || >=907676b130711fd1f627824559e92259db2061d1 <43015461662d41dcfb3bb95fadd8a2a42ad8eacf || >=907676b130711fd1f627824559e92259db2061d1 <6dc10494cfe27b6f1e9adb7e293293ae39c50b7c || >=907676b130711fd1f627824559e92259db2061d1 <d2c785733dfb853ea0b53984c75662a1af230a94 || >=907676b130711fd1f627824559e92259db2061d1 <fdbccddb7e7822016601829f95de4008e193f7bc || >=907676b130711fd1f627824559e92259db2061d1 <c3659273860bed0c8e573b865e3769abc51225a8 || >=907676b130711fd1f627824559e92259db2061d1 <6d2f142b1e4b203387a92519d9d2e34752a79dbb | fb6a4c376d454b425555b1b0bda36e99f56ec307, 43015461662d41dcfb3bb95fadd8a2a42ad8eacf, 6dc10494cfe27b6f1e9adb7e293293ae39c50b7c, d2c785733dfb853ea0b53984c75662a1af230a94, fdbccddb7e7822016601829f95de4008e193f7bc, c3659273860bed0c8e573b865e3769abc51225a8, 6d2f142b1e4b203387a92519d9d2e34752a79dbb |
| Linux/Linuxgeneric | 5.14 | Not reported |
Published upstream
May 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix double free issue for tx spare buffer In hns3_set_ringparam(), a temporary copy (tmp_rings) of the ring structure is created for rollback. However, the tx_spare pointer in the original ring handle is incorrectly left pointing to the old backup memory. Later, if memory allocation fails in hns3_init_all_ring() during the setup, the error path attempts to free all newly allocated rings. Since tx_spare contains a stale (non-NULL) pointer from the backup, it is mistaken for a newly allocated buffer and is erroneously freed, leading to a double-free of the backup memory. The root cause is that the tx_spare field was not cleared after its value was saved in tmp_rings, leaving a dangling pointer. Fix this by setting tx_spare to NULL in the original ring structure when the creation of the new `tx_spare` fails. This ensures the error cleanup path only frees genuinely newly allocated buffers.
Quoted source text, attributed separately from HOL analysis.