Answer in brief
CVE-2026-72022 records a Unknown severity vulnerability in llc: fix SAP refcount leak in llc_ui_autobind(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-72022 records a Unknown severity vulnerability in llc: fix SAP refcount leak in llc_ui_autobind(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <79dc4b508e3f2649390a1f745f7657813e5938ec || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <a2f9fa31ae021ef1fdcaf3ab17bd49f9223dd6a4 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b589a965184dde49c43b8caf5bcc65715a7b4ef2 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <c7881b6088276601beaccb7440b8d56eab0d65ae || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b2fc9955ddc7c4ca03be44b995193bd6486c62e1 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <61a7ff4a62003b55a15022567486741b3bd83914 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <21a537606fe35be2b85971a5fd35c0023b6ef98f || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <660667cd406648bbaffbd5c0d897c2263a852f11 | 79dc4b508e3f2649390a1f745f7657813e5938ec, a2f9fa31ae021ef1fdcaf3ab17bd49f9223dd6a4, b589a965184dde49c43b8caf5bcc65715a7b4ef2, c7881b6088276601beaccb7440b8d56eab0d65ae, b2fc9955ddc7c4ca03be44b995193bd6486c62e1, 61a7ff4a62003b55a15022567486741b3bd83914, 21a537606fe35be2b85971a5fd35c0023b6ef98f, 660667cd406648bbaffbd5c0d897c2263a852f11 |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: llc: fix SAP refcount leak in llc_ui_autobind() llc_ui_autobind() opens a SAP after choosing a dynamic LSAP. llc_sap_open() returns a reference owned by the caller, and llc_sap_add_socket() takes a second reference for the socket's membership in the SAP hash tables. llc_ui_bind() drops the caller's reference after adding the socket, but llc_ui_autobind() keeps it. When the socket is closed, llc_sap_remove_socket() releases only the socket reference, leaving the SAP on llc_sap_list with sk_count == 0. This is user-visible because repeated autobind and close cycles can consume all dynamic SAP values and make later autobinds fail with -EUSERS. Drop the caller's reference after a successful autobind, matching llc_ui_bind()'s ownership model.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <79dc4b508e3f2649390a1f745f7657813e5938ec || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <a2f9fa31ae021ef1fdcaf3ab17bd49f9223dd6a4 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b589a965184dde49c43b8caf5bcc65715a7b4ef2 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <c7881b6088276601beaccb7440b8d56eab0d65ae || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b2fc9955ddc7c4ca03be44b995193bd6486c62e1 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <61a7ff4a62003b55a15022567486741b3bd83914 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <21a537606fe35be2b85971a5fd35c0023b6ef98f || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <660667cd406648bbaffbd5c0d897c2263a852f11 | 79dc4b508e3f2649390a1f745f7657813e5938ec, a2f9fa31ae021ef1fdcaf3ab17bd49f9223dd6a4, b589a965184dde49c43b8caf5bcc65715a7b4ef2, c7881b6088276601beaccb7440b8d56eab0d65ae, b2fc9955ddc7c4ca03be44b995193bd6486c62e1, 61a7ff4a62003b55a15022567486741b3bd83914, 21a537606fe35be2b85971a5fd35c0023b6ef98f, 660667cd406648bbaffbd5c0d897c2263a852f11 |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: llc: fix SAP refcount leak in llc_ui_autobind() llc_ui_autobind() opens a SAP after choosing a dynamic LSAP. llc_sap_open() returns a reference owned by the caller, and llc_sap_add_socket() takes a second reference for the socket's membership in the SAP hash tables. llc_ui_bind() drops the caller's reference after adding the socket, but llc_ui_autobind() keeps it. When the socket is closed, llc_sap_remove_socket() releases only the socket reference, leaving the SAP on llc_sap_list with sk_count == 0. This is user-visible because repeated autobind and close cycles can consume all dynamic SAP values and make later autobinds fail with -EUSERS. Drop the caller's reference after a successful autobind, matching llc_ui_bind()'s ownership model.
Quoted source text, attributed separately from HOL analysis.