« Volver al listado

CVE-2026-72326

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cake: reject overhead values that underflow length

CAKE accepts signed overhead values and stores them in an s16, but the adjusted packet length calculation uses unsigned arithmetic. A negative effective length can therefore wrap to a large value.

Such configurations make rate accounting depend on integer wraparound rather than on the packet size userspace intended to model. A static netlink lower bound is not enough because packets reaching CAKE can be smaller than any reasonable manual-overhead allowance.

Fold the signed overhead adjustment into the existing datapath MPU clamp so negative adjusted lengths are clamped before link-layer framing adjustments.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72326",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "a729b7f0bd5bf4919306556aed614438f5174537",
              "lessThan": "f511dd7bf6077aa7afbe72914520553fedaacbb4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a729b7f0bd5bf4919306556aed614438f5174537",
              "lessThan": "e1df6cff03aad8c96e55a8b2a991e505c7a3ff6f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a729b7f0bd5bf4919306556aed614438f5174537",
              "lessThan": "297f459865360b46a887667cbf3aac6a6f013841",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a729b7f0bd5bf4919306556aed614438f5174537",
              "lessThan": "336c1e414fc0e9844d445174e8ada2a7dd8d1c4b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a729b7f0bd5bf4919306556aed614438f5174537",
              "lessThan": "bcdf3a3664f7d2c4e37e155f30f72ef33f041804",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a729b7f0bd5bf4919306556aed614438f5174537",
              "lessThan": "7aa0e64fea778a9e3df73e64da95367ff8ad2ea5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a729b7f0bd5bf4919306556aed614438f5174537",
              "lessThan": "f1e7807df5bf2d42a40266430e9f82f37633cdcf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a729b7f0bd5bf4919306556aed614438f5174537",
              "lessThan": "b7f97cae7ec1b6c3c32843c42be218690d310467",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/sched/sch_cake.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/sched/sch_cake.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:05.660",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/297f459865360b46a887667cbf3aac6a6f013841",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/336c1e414fc0e9844d445174e8ada2a7dd8d1c4b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7aa0e64fea778a9e3df73e64da95367ff8ad2ea5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b7f97cae7ec1b6c3c32843c42be218690d310467",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bcdf3a3664f7d2c4e37e155f30f72ef33f041804",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e1df6cff03aad8c96e55a8b2a991e505c7a3ff6f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f1e7807df5bf2d42a40266430e9f82f37633cdcf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f511dd7bf6077aa7afbe72914520553fedaacbb4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cake: reject overhead values that underflow length\n\nCAKE accepts signed overhead values and stores them in an s16, but the\nadjusted packet length calculation uses unsigned arithmetic.  A negative\neffective length can therefore wrap to a large value.\n\nSuch configurations make rate accounting depend on integer wraparound\nrather than on the packet size userspace intended to model.  A static\nnetlink lower bound is not enough because packets reaching CAKE can be\nsmaller than any reasonable manual-overhead allowance.\n\nFold the signed overhead adjustment into the existing datapath MPU clamp\nso negative adjusted lengths are clamped before link-layer framing\nadjustments."
    }
  ],
  "lastModified": "2026-08-17T06:18:36.153",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}