CVE-2026-72065

Source
https://cve.org/CVERecord?id=CVE-2026-72065
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72065.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72065
Downstream
Published
2026-08-15T05:52:18.801Z
Modified
2026-08-18T03:56:19.334603477Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net: mana: Validate the packet length reported by the NIC
Details

In the Linux kernel, the following vulnerability has been resolved:

net: mana: Validate the packet length reported by the NIC

Validate the packet length reported in the RX CQE before passing it to skb processing. The CQE is supplied by the NIC device and should not be blindly trusted.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72065.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f
Fixed
2e276b14b6d378372bf0152df89286cbe7632fb0
Fixed
6080189291d958604dcefe513a13900835ac982f
Fixed
6d13eaa13341a8f80aaf86f78591e1b1d393711d
Fixed
282c5214ca4eb3799158c76782646e86d2945d1b
Fixed
2e2a83b4998af4384e677d3b2ac08565274279bf

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72065.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72065.json"