CVE-2026-72065
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mana: Validate the packet length reported by the NIC
Validate the packet length reported in the RX CQE before passing it to skb processing. The CQE is supplied by the NIC device and should not be blindly trusted.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 2e276b14b6d378372bf0152df89286cbe7632fb0 | affected |
| Linux | Linux | ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 6080189291d958604dcefe513a13900835ac982f | affected |
| Linux | Linux | ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 6d13eaa13341a8f80aaf86f78591e1b1d393711d | affected |
| Linux | Linux | ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 282c5214ca4eb3799158c76782646e86d2945d1b | affected |
| Linux | Linux | ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 2e2a83b4998af4384e677d3b2ac08565274279bf | affected |
| Linux | Linux | 5.13 | affected |
| Linux | Linux | 0 < 5.13 | unaffected |
| Linux | Linux | 6.6.148 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.101 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.42 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/2e276b14b6d378372bf0152df89286cbe7632fb0
- https://git.kernel.org/stable/c/6080189291d958604dcefe513a13900835ac982f
- https://git.kernel.org/stable/c/6d13eaa13341a8f80aaf86f78591e1b1d393711d
- https://git.kernel.org/stable/c/282c5214ca4eb3799158c76782646e86d2945d1b
- https://git.kernel.org/stable/c/2e2a83b4998af4384e677d3b2ac08565274279bf
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.