Answer in brief
CVE-2026-68333 records a Unknown severity vulnerability in dpaa2-switch: put MAC endpoint device on disconnect. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=84cba72956fddf29ba666f885c39ed147024c125 <1f4ca61b7a93de3dfa5161bcd38ecb99bb091c38 || >=84cba72956fddf29ba666f885c39ed147024c125 <680eecc850d36a280df9780496bc603fec17b2d6 || >=84cba72956fddf29ba666f885c39ed147024c125 <26ac2d3602347f0377fbcd5214bc28a9d735ae68 || >=84cba72956fddf29ba666f885c39ed147024c125 <c27694ff6748e08fcd2fdba89018439d75b8198f || >=84cba72956fddf29ba666f885c39ed147024c125 <4c1eabbef7a1707635652e956e39db1269c3af2b | 1f4ca61b7a93de3dfa5161bcd38ecb99bb091c38, 680eecc850d36a280df9780496bc603fec17b2d6, 26ac2d3602347f0377fbcd5214bc28a9d735ae68, c27694ff6748e08fcd2fdba89018439d75b8198f, 4c1eabbef7a1707635652e956e39db1269c3af2b |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: put MAC endpoint device on disconnect fsl_mc_get_endpoint() returns the MAC endpoint device with a reference taken through device_find_child(). The switch port connect path stores that device in mac->mc_dev and keeps it for the lifetime of the connected MAC object. However, the disconnect path only closes the MAC and frees the dpaa2_mac object. It does not drop the endpoint device reference stored in mac->mc_dev, so every successful connect leaks that device reference when the MAC is later disconnected. Drop the endpoint device reference before freeing the dpaa2_mac object.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68333 records a Unknown severity vulnerability in dpaa2-switch: put MAC endpoint device on disconnect. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=84cba72956fddf29ba666f885c39ed147024c125 <1f4ca61b7a93de3dfa5161bcd38ecb99bb091c38 || >=84cba72956fddf29ba666f885c39ed147024c125 <680eecc850d36a280df9780496bc603fec17b2d6 || >=84cba72956fddf29ba666f885c39ed147024c125 <26ac2d3602347f0377fbcd5214bc28a9d735ae68 || >=84cba72956fddf29ba666f885c39ed147024c125 <c27694ff6748e08fcd2fdba89018439d75b8198f || >=84cba72956fddf29ba666f885c39ed147024c125 <4c1eabbef7a1707635652e956e39db1269c3af2b | 1f4ca61b7a93de3dfa5161bcd38ecb99bb091c38, 680eecc850d36a280df9780496bc603fec17b2d6, 26ac2d3602347f0377fbcd5214bc28a9d735ae68, c27694ff6748e08fcd2fdba89018439d75b8198f, 4c1eabbef7a1707635652e956e39db1269c3af2b |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: put MAC endpoint device on disconnect fsl_mc_get_endpoint() returns the MAC endpoint device with a reference taken through device_find_child(). The switch port connect path stores that device in mac->mc_dev and keeps it for the lifetime of the connected MAC object. However, the disconnect path only closes the MAC and frees the dpaa2_mac object. It does not drop the endpoint device reference stored in mac->mc_dev, so every successful connect leaks that device reference when the MAC is later disconnected. Drop the endpoint device reference before freeing the dpaa2_mac object.
Quoted source text, attributed separately from HOL analysis.