CVE-2026-72340
Last modified
CVE-2026-72340 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap: fix races on the shared Super VCAP block The VCAP instances on a chip are not independent, yet they are locked independently. On sparx5 and lan969x the IS0 and IS2 instances are backed by the same Super VCAP hardware block and share its cache and command registers: every access drives the shared VCAP_SUPER_CTRL register and moves data through the shared cache registers. Accessing one instance therefore races with accessing another. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap: fix races on the shared Super VCAP block The VCAP instances on a chip are not independent, yet they are locked independently. On sparx5 and lan969x the IS0 and IS2 instances are backed by the same Super VCAP hardware block and share its cache and command registers: every access drives the shared VCAP_SUPER_CTRL register and moves data through the shared cache registers. Accessing one instance therefore races with accessing another. The per-instance admin->lock cannot prevent this, as each instance takes a different lock. The locking issue is mostly disguised by the fact that the core usage of the vcap api runs under rtnl. However, the full rule dump in debugfs decodes rules straight from hardware (a READ command followed by a cache read) and runs outside rtnl, so it races a concurrent tc-flower rule write to another Super VCAP instance. Besides corrupting the dump, the read repopulates the shared cache between the writers cache fill and its write command, so the writer commits the wrong data and corrupts the hardware entry. Introduce vcap_lock() and vcap_unlock() helpers and route every rule lock site in the VCAP API and its debugfs code through them. Replace the per-instance admin->lock with a single mutex in struct vcap_control that serializes access to all instances. The helpers reach it through a new admin->vctrl back-pointer, and the clients initialise and destroy the control lock instead of a per-instance one. No path holds more than one instance lock, so collapsing them onto a single mutex cannot self-deadlock.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 71c9de995260222e739020104d477af4775a6d26, < 786456d0a244bbd405dfc60e4de51f8b348b9cb1; >= 71c9de995260222e739020104d477af4775a6d26, < 49806bef9572a2e012610517bc14ed0a4db0d1fc; >= 71c9de995260222e739020104d477af4775a6d26, < 1e71a40d101547380590db582213c1f1dce1f041; >= 71c9de995260222e739020104d477af4775a6d26, < 952928564cc5fdb06f92d7e25c6cd2e1d816362b; >= 71c9de995260222e739020104d477af4775a6d26, < d7a8d500d7e42837bd8dce40cb52c97c6e8706a9 |
| Linux | Linux | 6.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72340?
How severe is CVE-2026-72340?
How do I fix CVE-2026-72340?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72335In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72336In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72337In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72338In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72339In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-7234A weakness has been identified in BrowserOperator browser-op…7.3
- CVE-2026-72341In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72342In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-72343In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-72344In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72345In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72346In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-72340?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
