Improper input validation in Linux kernel - CVE-2026-72065
Published: August 16, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to improper input validation in the mana RX completion queue handling in mana_process_rx_cqe() when processing packet length values reported by the NIC. An attacker with physical access can supply an invalid packet length via a malicious or compromised NIC device to cause a denial of service.
The reported packet length is supplied by the NIC device and is not sufficiently validated before skb processing.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)
How to mitigate CVE-2026-72065
linux (Ubuntu package) - addressed in versions 7.0.0-34.34, 7.0.0-34.34.1, 7.0.0-34.34~24.04.1, 7.0.0-1012.12~24.04.1, 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14, 7.0.0-1020.20
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14
External References
- https://git.kernel.org/stable/c/282c5214ca4eb3799158c76782646e86d2945d1b
- https://git.kernel.org/stable/c/2e276b14b6d378372bf0152df89286cbe7632fb0
- https://git.kernel.org/stable/c/2e2a83b4998af4384e677d3b2ac08565274279bf
- https://git.kernel.org/stable/c/6080189291d958604dcefe513a13900835ac982f
- https://git.kernel.org/stable/c/6d13eaa13341a8f80aaf86f78591e1b1d393711d