Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-72065Potential RCE in Linux kernel (MANA driver)

In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by the NIC Validate the packet length reported in the RX CQE before passing it to skb processing. The CQE is supplied by the NIC device and should not be blindly trusted.

View on NVD

Analysis

A critical vulnerability has been identified in the Linux kernel's Microsoft Azure Network Adapter (MANA) driver. The driver fails to validate packet lengths reported by the hardware, which can lead to memory corruption. This is a significant risk for any Linux-based workloads running on Azure infrastructure.

Relevant roles

LinuxCloudCBackendDockerciberseguridad

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH

EPSS

Probability of exploitation (next 30 days): 0.0066 (0.7%)
Percentile: 48.7%
EPSS: 2026-08-23

Technical description

In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by the NIC Validate the packet length reported in the RX CQE before passing it to skb processing. The CQE is supplied by the NIC device and should not be blindly trusted.

Published: 8/15/2026, 6:21:16 AM
Last modified: 8/23/2026, 1:16:39 PM

References

HomeEventsBlogResourcesCoursesTeam