Answer in brief
CVE-2026-68331 records a Unknown severity vulnerability in dpaa2-eth: put MAC endpoint device on disconnect. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=71947923089353f23f4f210864903c4dcf2c1696 <915012e923316b8b5d5bf8fc771617b47bd7572d || >=71947923089353f23f4f210864903c4dcf2c1696 <e23e4a3b9dfd893469c731318d409cdf04fb1ddf || >=71947923089353f23f4f210864903c4dcf2c1696 <f112df0744e2d77baa68eeebb860021bbaaa022a || >=71947923089353f23f4f210864903c4dcf2c1696 <a3cecf169cc652b558d08661bb6ce55e4c933ec0 || >=71947923089353f23f4f210864903c4dcf2c1696 <b4b201cc93ff70150853aba03e14d314d1980ca0 | 915012e923316b8b5d5bf8fc771617b47bd7572d, e23e4a3b9dfd893469c731318d409cdf04fb1ddf, f112df0744e2d77baa68eeebb860021bbaaa022a, a3cecf169cc652b558d08661bb6ce55e4c933ec0, b4b201cc93ff70150853aba03e14d314d1980ca0 |
| Linux/Linuxgeneric | 5.5 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: dpaa2-eth: put MAC endpoint device on disconnect fsl_mc_get_endpoint() returns the MAC endpoint device with a reference taken through device_find_child(). The Ethernet connect path stores that device in mac->mc_dev and keeps it for the lifetime of the connected MAC object. However, the disconnect path only disconnects and closes the MAC before freeing the dpaa2_mac object. It does not drop the endpoint device reference stored in mac->mc_dev, so every successful connect leaks that device reference when the MAC is later disconnected. Drop the endpoint device reference after closing the MAC and before freeing the dpaa2_mac object.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68331 records a Unknown severity vulnerability in dpaa2-eth: put MAC endpoint device on disconnect. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=71947923089353f23f4f210864903c4dcf2c1696 <915012e923316b8b5d5bf8fc771617b47bd7572d || >=71947923089353f23f4f210864903c4dcf2c1696 <e23e4a3b9dfd893469c731318d409cdf04fb1ddf || >=71947923089353f23f4f210864903c4dcf2c1696 <f112df0744e2d77baa68eeebb860021bbaaa022a || >=71947923089353f23f4f210864903c4dcf2c1696 <a3cecf169cc652b558d08661bb6ce55e4c933ec0 || >=71947923089353f23f4f210864903c4dcf2c1696 <b4b201cc93ff70150853aba03e14d314d1980ca0 | 915012e923316b8b5d5bf8fc771617b47bd7572d, e23e4a3b9dfd893469c731318d409cdf04fb1ddf, f112df0744e2d77baa68eeebb860021bbaaa022a, a3cecf169cc652b558d08661bb6ce55e4c933ec0, b4b201cc93ff70150853aba03e14d314d1980ca0 |
| Linux/Linuxgeneric | 5.5 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: dpaa2-eth: put MAC endpoint device on disconnect fsl_mc_get_endpoint() returns the MAC endpoint device with a reference taken through device_find_child(). The Ethernet connect path stores that device in mac->mc_dev and keeps it for the lifetime of the connected MAC object. However, the disconnect path only disconnects and closes the MAC before freeing the dpaa2_mac object. It does not drop the endpoint device reference stored in mac->mc_dev, so every successful connect leaks that device reference when the MAC is later disconnected. Drop the endpoint device reference after closing the MAC and before freeing the dpaa2_mac object.
Quoted source text, attributed separately from HOL analysis.