Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-72065RCE potencial en el kernel Linux (driver MANA)

In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by the NIC Validate the packet length reported in the RX CQE before passing it to skb processing. The CQE is supplied by the NIC device and should not be blindly trusted.

Ver en NVD

Análisis

A critical vulnerability has been identified in the Linux kernel's Microsoft Azure Network Adapter (MANA) driver. The driver fails to validate packet lengths reported by the hardware, which can lead to memory corruption. This is a significant risk for any Linux-based workloads running on Azure infrastructure.

Roles relevantes

LinuxCloudCBackendDockerciberseguridad

Severidad

Puntaje: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH

EPSS

Probabilidad de explotación (próx. 30 días): 0.0066 (0.7%)
Percentil: 48.7%
EPSS: 2026-08-23

Descripción técnica

In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by the NIC Validate the packet length reported in the RX CQE before passing it to skb processing. The CQE is supplied by the NIC device and should not be blindly trusted.

Publicada: 15/8/2026, 6:21:16
Última modificación: 23/8/2026, 13:16:39

Referencias

InicioEventosBlogRecursosCursosEquipo