Out-of-bounds read in Linux kernel - CVE-2026-72351

 

Out-of-bounds read in Linux kernel - CVE-2026-72351

Published: August 16, 2026


Vulnerability identifier: #VU143089
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72351
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in gue_remcsum() and gue_gro_remcsum() when processing malformed GUE packets with the REMCSUM private flag set but without the required REMCSUM metadata fields. A remote attacker can send a specially crafted packet to disclose sensitive information.

The issue occurs because option validation accepts packets that contain only the private flags field even when additional REMCSUM start and offset fields are expected.


Affected software

Linux kernel
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)

How to mitigate CVE-2026-72351

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 7.0.0-34.34, 7.0.0-34.34.1, 7.0.0-34.34~24.04.1, 7.0.0-1012.12~24.04.1, 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14, 7.0.0-1020.20
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14

External References

Related Security Bulletins