Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-72041Vulnerabilidad crítica en el kernel de Linux (espintcp)

In the Linux kernel, the following vulnerability has been resolved: espintcp: use sk_msg_free_partial to fix partial send sk_msg_free_partial() ensures consistency of the skmsg at every iteration, without having to manually handle uncharges and offsets. This simplifies the code, and fixes some bugs in skmsg accounting when we don't send the full contents.

Ver en NVD

Análisis

A critical vulnerability was identified in the Linux kernel's espintcp implementation. This flaw in network socket message accounting could allow a remote attacker to cause memory corruption or system instability, making kernel updates essential for systems using IPsec over TCP.

Roles relevantes

LinuxBackendCloudKubernetesDockerciberseguridad

Severidad

Puntaje: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH

EPSS

Probabilidad de explotación (próx. 30 días): 0.0063 (0.6%)
Percentil: 47.2%
EPSS: 2026-08-23

Descripción técnica

In the Linux kernel, the following vulnerability has been resolved: espintcp: use sk_msg_free_partial to fix partial send sk_msg_free_partial() ensures consistency of the skmsg at every iteration, without having to manually handle uncharges and offsets. This simplifies the code, and fixes some bugs in skmsg accounting when we don't send the full contents.

Publicada: 15/8/2026, 6:21:13
Última modificación: 23/8/2026, 13:16:38

Referencias

InicioEventosBlogRecursosCursosEquipo