CVE-2026-72045

Source
https://cve.org/CVERecord?id=CVE-2026-72045
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72045.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72045
Downstream
Published
2026-08-15T05:52:04.038Z
Modified
2026-08-18T03:56:36.602807269Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
Details

In the Linux kernel, the following vulnerability has been resolved:

octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF

rvumboxhandlerlmtsttblsetup() uses req->basepcifunc as a direct index into the LMT map table to read another function's LMTLINE physical base address and copy it into the caller's own LMT map table entry. The mailbox dispatcher authenticates req->hdr.pcifunc from the IRQ source, but req->base_pcifunc is a separate payload field and is not sanitized.

Reject the request with -EPERM when a VF caller's basepcifunc is not a valid function under its own PF. ispffuncvalid() bounds the FUNC field to the PF's configured VF count, keeping the computed index inside the caller's own slot block.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72045.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
893ae97214c385be02f8ec097298cc48c7f0d905
Fixed
e9c5b03208507dd6d58b0c23a2c60b5c2f4c1b11
Fixed
54535692bec9ef464adc714108eb19e49e38b5a2
Fixed
c73b8795b45f4ad5a95120d2e9b435ea4616e08e
Fixed
59da37fee81a8d76079313348ca13c5bc90dd6ae
Fixed
8cdcf3d2caacdee7ddd363705fb4d93b0c1a0915

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72045.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72045.json"