CVE-2026-72065

Summary

In the Linux kernel, the following vulnerability has been resolved:

net: mana: Validate the packet length reported by the NIC

Validate the packet length reported in the RX CQE before passing it to skb processing. The CQE is supplied by the NIC device and should not be blindly trusted.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 2e276b14b6d378372bf0152df89286cbe7632fb0affected
LinuxLinuxca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 6080189291d958604dcefe513a13900835ac982faffected
LinuxLinuxca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 6d13eaa13341a8f80aaf86f78591e1b1d393711daffected
LinuxLinuxca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 282c5214ca4eb3799158c76782646e86d2945d1baffected
LinuxLinuxca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 2e2a83b4998af4384e677d3b2ac08565274279bfaffected
LinuxLinux5.13affected
LinuxLinux0 < 5.13unaffected
LinuxLinux6.6.148 <= 6.6.*unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References