CVE-2026-72312

Source
https://cve.org/CVERecord?id=CVE-2026-72312
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72312.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72312
Downstream
Published
2026-08-15T05:55:27.817Z
Modified
2026-08-18T03:56:41.294501631Z
Severity
  • 7.9 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H CVSS Calculator
Summary
octeontx2-af: fix VF bringup affecting PF promiscuous state
Details

In the Linux kernel, the following vulnerability has been resolved:

octeontx2-af: fix VF bringup affecting PF promiscuous state

Mbox handling of nixsetrxmode for a VF with promiscuous and allmulti flags set to false causes deletion of the PF's promiscuous and allmulti MCAM rules. This occurs because the APIs that enable/disable these rules operate only on the PF, even when the mbox request is made via a VF interface.

Guard both rvunpcenableallmultientry() and rvunpcenablepromiscentry() disable paths with an is_vf() check so that a VF bringing up or tearing down its interface cannot inadvertently clear the PF's MCAM rules.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72312.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
967db3529ecac305d230aa4e60abddf6ab63543a
Fixed
daa2451640a3e0727fd598f5c2ccb8bb4d5a8b9c
Fixed
212c59e5e416859579272288fd325148fc316109
Fixed
53e17d9ed779ad25870abb9c31bc294c71a2278c
Fixed
3de77d2f34c2bc2acaedabc2c5e0a561b85c283a
Fixed
3cf83432e0561aef6d7ec2664909d12d0ff0ffc1
Fixed
fabb881df322da25442f98d23f5fa371e3c78ec4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72312.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72312.json"