CVE-2026-72064
In the Linux kernel, the following vulnerability has been resolved:
net: mana: Sync page pool RX frags for CPU
MANA allocates RX buffers from page pool fragments when frag_count is greater than 1. In that case the buffers remain DMA mapped by page pool and the RX completion path does not call dma_unmap_single(). As a result, the implicit sync-for-CPU normally performed by dma_unmap_single() is missing before the packet data is passed to the networking stack.
This breaks RX on configurations which require explicit DMA syncing, for example when booted with swiotlb=force.
Fix this by recording the page pool page and DMA sync offset when the RX buffer is allocated, and syncing the received packet range for CPU access before handing the RX buffer to the stack.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.55%
- Percentil entre todas las CVEs puntuadas: 44
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access25 %
Vulnerabilidad en controlador de red MANA del kernel Linux con acceso remoto sin autenticación (AV:N/PR:N). El defecto en sincronización DMA permite corrupción de datos RX o denegación de servicio en configuraciones con swiotlb=force.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72064",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "730ff06d3f5cc2ce0348414b78c10528b767d4a3",
"lessThan": "bc650dd5ce6434286b96e2b26a41af81f679cc7c",
"versionType": "git"
},
{
"status": "affected",
"version": "730ff06d3f5cc2ce0348414b78c10528b767d4a3",
"lessThan": "c72a0f09c57f92113df69f9b902d11c9e4b132f5",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/ethernet/microsoft/mana/mana_en.c",
"include/net/mana/mana.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.18",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/microsoft/mana/mana_en.c",
"include/net/mana/mana.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:21:16.003",
"references": [
{
"url": "https://git.kernel.org/stable/c/bc650dd5ce6434286b96e2b26a41af81f679cc7c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c72a0f09c57f92113df69f9b902d11c9e4b132f5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Sync page pool RX frags for CPU\n\nMANA allocates RX buffers from page pool fragments when frag_count is\ngreater than 1. In that case the buffers remain DMA mapped by page pool\nand the RX completion path does not call dma_unmap_single(). As a result,\nthe implicit sync-for-CPU normally performed by dma_unmap_single() is\nmissing before the packet data is passed to the networking stack.\n\nThis breaks RX on configurations which require explicit DMA syncing, for\nexample when booted with swiotlb=force.\n\nFix this by recording the page pool page and DMA sync offset when the RX\nbuffer is allocated, and syncing the received packet range for CPU access\nbefore handing the RX buffer to the stack."
}
],
"lastModified": "2026-08-17T06:18:04.810",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}