CVE-2026-72407

Critical

In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network offset in geneve_gro_complete() Even with both paths gated on gs->gro_hint, geneve_gro_complete() re-derives the inner dispatch type and length from the packet and the current gs->gro_hint, independently of geneve_gro_receive(). The two can disagree if gs->gro_hint flips under a concurrent geneve_quiesce()/ geneve_unquiesce() (sk_user_data is NULL across a synchronize_net()), or if the re-read option bytes differ from the ones receive parsed. geneve_gro_receive() already records the inner network header position in NAPI_GRO_CB()->inner_network_offset. Have geneve_gro_complete() compute the offset it is about to dispatch at, adding ETH_HLEN in the ETH_P_TEB case where eth_gro_complete() steps over the inner MAC header, and bail out if it lands past inner_network_offset. Use a lower bound rather than exact equality: between gh_len and the inner L3 header, geneve_gro_receive() may also have pulled an inner VLAN tag (vlan_gro_receive() advances the recorded offset past it), which only moves inner_network_offset further out. A valid frame therefore always satisfies inner_nh <= inner_network_offset, while a gh_len inflated by a hint gro_receive() did not honour dispatches past the validated inner header, i.e. the out-of-bounds completion. Only the latter is rejected.

Package Linux Kernel
Published 2026-08-15
Last modified 2026-08-17
CVSS version 3.1
Patch available
Yes

CVSS 3.1 score

10.0

out of 10
Critical
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected versions

Linux kernel versions 7.0 and later are affected. Fixed in 7.1.5, 7.2 and their respective stable series.

Affected from
≥ 7.0
Fixed in
✓ 7.1.5 7.1.x ✓ 7.2

Frequently asked questions

  • What is CVE-2026-72407?

    CVE-2026-72407 is a Critical severity Linux kernel vulnerability with a CVSS score of 10.0 out of 10 . It affects Linux kernel versions from 7.0 onward and has been patched in 7.1.5 and 7.2. CVE-2026-72407 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • What is the CVSS score for CVE-2026-72407?

    CVE-2026-72407 has a CVSS score of 10.0 out of 10, rated Critical severity (CVSS 3.1). The vector string is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H .

  • Is there a patch available for CVE-2026-72407?

    Yes. CVE-2026-72407 has been patched. Fixed versions include 7.1.5 and 7.2. If you are running Linux kernel 7.0 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-72407 actively exploited?

    No. CVE-2026-72407 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.