vulnti.work

In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by the NIC Validate the packet length reported in the RX CQE before passing it to …

Critical CVSS 9.8
CVECVE-2026-72065
First seen2026-08-23 15:16 UTC
Disclosed2026-08-15 06:21 UTC
Last updated2026-08-23 15:16 UTC
Channel statusauto

Summary

In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by the NIC Validate the packet length reported in the RX CQE before passing it to skb processing. The CQE is supplied by the NIC device and should not be blindly trusted.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD