CVE-2026-72065 (GCVE-0-2026-72065)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by the NIC Validate the packet length reported in the RX CQE before passing it to skb processing. The CQE is supplied by the NIC device and should not be blindly trusted.
Impacted products
Vendor Product Version
Linux Linux Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f
Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f
Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f
Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f
Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f
Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f
Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/microsoft/mana/mana_en.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "a631f82f89c76084ad5b2b9c043d3b391ffa56d8",
              "status": "affected",
              "version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
              "versionType": "git"
            },
            {
              "lessThan": "d2568e64d01f480200063fadd67d6938f676c66f",
              "status": "affected",
              "version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
              "versionType": "git"
            },
            {
              "lessThan": "2e276b14b6d378372bf0152df89286cbe7632fb0",
              "status": "affected",
              "version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
              "versionType": "git"
            },
            {
              "lessThan": "6080189291d958604dcefe513a13900835ac982f",
              "status": "affected",
              "version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
              "versionType": "git"
            },
            {
              "lessThan": "6d13eaa13341a8f80aaf86f78591e1b1d393711d",
              "status": "affected",
              "version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
              "versionType": "git"
            },
            {
              "lessThan": "282c5214ca4eb3799158c76782646e86d2945d1b",
              "status": "affected",
              "version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
              "versionType": "git"
            },
            {
              "lessThan": "2e2a83b4998af4384e677d3b2ac08565274279bf",
              "status": "affected",
              "version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/microsoft/mana/mana_en.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "lessThan": "5.13",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.217",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.184",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.148",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.217",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.184",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.148",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.101",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.42",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.5",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Validate the packet length reported by the NIC\n\nValidate the packet length reported in the RX CQE before passing it\nto skb processing. The CQE is supplied by the NIC device and should\nnot be blindly trusted."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - On internet-facing Azure VMs, remote packets drive MANA RX through IRQ/NAPI into mana_poll_rx_cq()/mana_process_rx_cqe(), where device-written RX CQE pkt_len is trusted and passed to skb/XDP processing without bounds checks against rxq-\u003edatasize.\nAC:L - The attacker can repeatedly send traffic to trigger RX completions until the MANA backend reports pkt_len above rxq-\u003edatasize; once that CQE arrives, mana_refill_rx_oob() and mana_rx_skb() misuse the length deterministically with no race or special memory layout.\nPR:N - The vulnerable path is the netdev NAPI receive handler before any socket or credential checks; an unauthenticated remote sender only needs packets routed to the VM\u0027s MANA interface, with no local account or capability on the victim.\nUI:N - RX CQEs are handled automatically from hardware interrupts and NAPI polling once the interface is up; no victim mount, ioctl, or other interactive action is required beyond normal network reception.\nS:U - Out-of-bounds access and crashes occur in the guest kernel processing MANA RX buffers; impact stays within that kernel security authority and does not by itself cross a VM/host or IOMMU boundary.\nC:H - Unchecked pkt_len is used in page_pool_dma_sync_for_cpu(), xdp_prepare_buff()/bpf_prog_run_xdp(), and skb_put()/eth_type_trans(), enabling reads well past the DMA-mapped rxq-\u003edatasize region and leaking adjacent kernel heap/page memory.\nI:H - Oversized pkt_len expands skb and XDP data bounds beyond the posted RX buffer, corrupting adjacent kernel memory and providing attacker-influenced metadata/control corruption primitives consistent with high integrity impact for OOB memory corruption.\nA:H - Processing an oversized pkt_len can kernel oops/panic from skb_put bounds failures or unmapped reads in softirq/NAPI context, and the remote attacker can retrigger the condition for sustained denial of service."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-23T12:46:40.741Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a631f82f89c76084ad5b2b9c043d3b391ffa56d8"
        },
        {
          "url": "https://git.kernel.org/stable/c/d2568e64d01f480200063fadd67d6938f676c66f"
        },
        {
          "url": "https://git.kernel.org/stable/c/2e276b14b6d378372bf0152df89286cbe7632fb0"
        },
        {
          "url": "https://git.kernel.org/stable/c/6080189291d958604dcefe513a13900835ac982f"
        },
        {
          "url": "https://git.kernel.org/stable/c/6d13eaa13341a8f80aaf86f78591e1b1d393711d"
        },
        {
          "url": "https://git.kernel.org/stable/c/282c5214ca4eb3799158c76782646e86d2945d1b"
        },
        {
          "url": "https://git.kernel.org/stable/c/2e2a83b4998af4384e677d3b2ac08565274279bf"
        }
      ],
      "title": "net: mana: Validate the packet length reported by the NIC",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-72065",
    "datePublished": "2026-08-15T05:52:18.801Z",
    "dateReserved": "2026-08-09T03:40:39.903Z",
    "dateUpdated": "2026-08-23T12:46:40.741Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…