---
cve: "CVE-2026-72312"
severity: "HIGH"
cvss: 7.9
epss: "15%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-08-15 06:22:04"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-09T06:04:59+02:00"
---

# CVE-2026-72312

> 7.9 HIGH

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

octeontx2-af: fix VF bringup affecting PF promiscuous state

Mbox handling of nix_set_rx_mode for a VF with promiscuous and
all_multi flags set to false causes deletion of the PF's promiscuous
and allmulti MCAM rules. This occurs because the APIs that
enable/disable these rules operate only on the PF, even when the
mbox request is made via a VF interface.

Guard both rvu_npc_enable_allmulti_entry() and
rvu_npc_enable_promisc_entry() disable paths with an is_vf() check so
that a VF bringing up or tearing down its interface cannot inadvertently
clear the PF's MCAM rules.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 6.1.178
- Kernel ≥ 6.6.145
- Kernel ≥ 6.12.97
- Kernel ≥ 6.18.40
- Kernel ≥ 7.1.5

## Referenzen

- <https://git.kernel.org/stable/c/daa2451640a3e0727fd598f5c2ccb8bb4d5a8b9c>
- <https://git.kernel.org/stable/c/212c59e5e416859579272288fd325148fc316109>
- <https://git.kernel.org/stable/c/53e17d9ed779ad25870abb9c31bc294c71a2278c>
- <https://git.kernel.org/stable/c/3de77d2f34c2bc2acaedabc2c5e0a561b85c283a>
- <https://git.kernel.org/stable/c/3cf83432e0561aef6d7ec2664909d12d0ff0ffc1>
- <https://git.kernel.org/stable/c/fabb881df322da25442f98d23f5fa371e3c78ec4>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-72312) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
