{"id":"CVE-2026-72312","summary":"octeontx2-af: fix VF bringup affecting PF promiscuous state","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: fix VF bringup affecting PF promiscuous state\n\nMbox handling of nix_set_rx_mode for a VF with promiscuous and\nall_multi flags set to false causes deletion of the PF's promiscuous\nand allmulti MCAM rules. This occurs because the APIs that\nenable/disable these rules operate only on the PF, even when the\nmbox request is made via a VF interface.\n\nGuard both rvu_npc_enable_allmulti_entry() and\nrvu_npc_enable_promisc_entry() disable paths with an is_vf() check so\nthat a VF bringing up or tearing down its interface cannot inadvertently\nclear the PF's MCAM rules.","modified":"2026-08-18T03:56:41.294501631Z","published":"2026-08-15T05:55:27.817Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72312.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/212c59e5e416859579272288fd325148fc316109"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3cf83432e0561aef6d7ec2664909d12d0ff0ffc1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3de77d2f34c2bc2acaedabc2c5e0a561b85c283a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/53e17d9ed779ad25870abb9c31bc294c71a2278c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/daa2451640a3e0727fd598f5c2ccb8bb4d5a8b9c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fabb881df322da25442f98d23f5fa371e3c78ec4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72312.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72312"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"967db3529ecac305d230aa4e60abddf6ab63543a"},{"fixed":"daa2451640a3e0727fd598f5c2ccb8bb4d5a8b9c"},{"fixed":"212c59e5e416859579272288fd325148fc316109"},{"fixed":"53e17d9ed779ad25870abb9c31bc294c71a2278c"},{"fixed":"3de77d2f34c2bc2acaedabc2c5e0a561b85c283a"},{"fixed":"3cf83432e0561aef6d7ec2664909d12d0ff0ffc1"},{"fixed":"fabb881df322da25442f98d23f5fa371e3c78ec4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72312.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.14.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.97"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.40"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72312.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H"}]}