CVE-2026-72060

Source
https://cve.org/CVERecord?id=CVE-2026-72060
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72060.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72060
Downstream
Published
2026-08-15T05:52:15.099Z
Modified
2026-08-18T03:31:19.253567671Z
Summary
net: ethernet: ti: icssg: guard PA stat lookups
Details

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: ti: icssg: guard PA stat lookups

icssgndogetstats64() unconditionally calls emacgetstatbyname() with FW PA stat names regardless of whether the PA stats block is present on the hardware. emacgetstatbyname() already guards the PA stats lookup with if (emac->prueth->pa_stats); when that pointer is NULL the lookup falls through to netdeverr() and returns -EINVAL. Because ndogetstats64 is polled regularly by the networking stack this produces thousands of log entries of the form:

icssg-prueth icssg1-eth end0: Invalid stats FWRXERROR

A secondary consequence is that the int(-EINVAL) return value is implicitly widened to a near-ULLONG_MAX unsigned value when accumulated into the _u64 fields of rtnllinkstats64, silently corrupting the rxerrors, rxdropped and txdropped counters reported by ip -s link.

Every other PA-aware code path in the driver is already guarded with the same if (emac->prueth->pa_stats) check. Apply the same guard here.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72060.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0d15a26b247d25cd012134bf8825128fedb15cc9
Fixed
121c5f31c3fb70d4a23e8a084f5cb8b3ec63be8d
Fixed
b3763f7e22ecaa7ad79bf44bf41816d488edbcf8
Fixed
27b9daba50609335db6ca81e4cccf50ded21ec76

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72060.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72060.json"