In the Linux kernel, the following vulnerability has been resolved:
netdev-genl: report NAPI thread PID in the caller's pid namespace
netdevnlnapifillone() reports the NAPI kthread PID in NETDEVANAPIPID using taskpid_nr(), which returns the PID in the initial pid namespace.
NETDEVCMDNAPIGET does not have GENLADMIN_PERM and the netdev genl family is netnsok, so a caller in a child pid namespace can issue it. That caller then sees the kthread's global PID, even though the kthread is not visible in its pid namespace, where the value should be 0.
Translate the PID through the caller's pid namespace, the same way commit 3799c2570982 ("iouring/fdinfo: translate SqThread PID through caller's pidns") did for the iouring SQPOLL thread. The doit and dumpit paths both run synchronously in the caller's context, so taskactivepidns(current) is the caller's pid namespace.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72127.json"
}