CVE-2026-72127
In the Linux kernel, the following vulnerability has been resolved:
netdev-genl: report NAPI thread PID in the caller's pid namespace
netdev_nl_napi_fill_one() reports the NAPI kthread PID in NETDEV_A_NAPI_PID using task_pid_nr(), which returns the PID in the initial pid namespace.
NETDEV_CMD_NAPI_GET does not have GENL_ADMIN_PERM and the netdev genl family is netnsok, so a caller in a child pid namespace can issue it. That caller then sees the kthread's global PID, even though the kthread is not visible in its pid namespace, where the value should be 0.
Translate the PID through the caller's pid namespace, the same way commit 3799c2570982 ("io_uring/fdinfo: translate SqThread PID through caller's pid_ns") did for the io_uring SQPOLL thread.
Leer descripción completaMostrar menos
The doit and dumpit paths both run synchronously in the caller's context, so task_active_pid_ns(current) is the caller's pid namespace.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72127",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "db4704f4e4dfce835e934609fca735a648ce26e8",
"lessThan": "fb18095389fe81f140d39585a2624aca9d42227e",
"versionType": "git"
},
{
"status": "affected",
"version": "db4704f4e4dfce835e934609fca735a648ce26e8",
"lessThan": "5e4c8e08ce95730c87d6ada0bdbe1131a3c06393",
"versionType": "git"
},
{
"status": "affected",
"version": "db4704f4e4dfce835e934609fca735a648ce26e8",
"lessThan": "fd750b694f1f9e1ecb8ca19314e4e21edbb15f42",
"versionType": "git"
},
{
"status": "affected",
"version": "db4704f4e4dfce835e934609fca735a648ce26e8",
"lessThan": "1f24c0d01db214c9e661915e9972404c96ca73c0",
"versionType": "git"
}
],
"programFiles": [
"net/core/netdev-genl.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/core/netdev-genl.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:21:30.113",
"references": [
{
"url": "https://git.kernel.org/stable/c/1f24c0d01db214c9e661915e9972404c96ca73c0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5e4c8e08ce95730c87d6ada0bdbe1131a3c06393",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fb18095389fe81f140d39585a2624aca9d42227e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fd750b694f1f9e1ecb8ca19314e4e21edbb15f42",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetdev-genl: report NAPI thread PID in the caller's pid namespace\n\nnetdev_nl_napi_fill_one() reports the NAPI kthread PID in NETDEV_A_NAPI_PID\nusing task_pid_nr(), which returns the PID in the initial pid namespace.\n\nNETDEV_CMD_NAPI_GET does not have GENL_ADMIN_PERM and the netdev genl family\nis netnsok, so a caller in a child pid namespace can issue it. That caller\nthen sees the kthread's global PID, even though the kthread is not visible\nin its pid namespace, where the value should be 0.\n\nTranslate the PID through the caller's pid namespace, the same way commit\n3799c2570982 (\"io_uring/fdinfo: translate SqThread PID through caller's\npid_ns\") did for the io_uring SQPOLL thread. The doit and dumpit paths both\nrun synchronously in the caller's context, so task_active_pid_ns(current) is\nthe caller's pid namespace."
}
],
"lastModified": "2026-08-17T06:18:12.363",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}