CVE-2026-72045
rvu driver flaw lets VF copy another function's LMTLINE, enabling cross-function DMA access.
Is CVE-2026-72045 being exploited?
Not confirmed. CVE-2026-72045 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.17% probability of exploitation in the next 30 days.
How severe is CVE-2026-72045?
CVE-2026-72045 is rated High. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72045?
Yes. A fix has been recorded for CVE-2026-72045. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72045 affect?
CVE-2026-72045 affects Linux kernel (rvu driver, octeontx2 cn10k), Marvell/Cavium OcteonTX2 CN10K NICs, Platforms using SR-IOV VFs on CN10K. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72045?
Apply vendor/kernel patch that enforces PF bounds on base_pcifunc; restrict/untrust VFs until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Malicious VF can copy another function's LMTLINE base, enabling cross-tenant DMA access, data theft, privilege escalation or device/host RCE.
Immediate action required
- affected>= 893ae97214c385be02f8ec097298cc48c7f0d905 and < 04c014e49b9f53d58a8f94adece8a0af3ae1b85c
- affected>= 893ae97214c385be02f8ec097298cc48c7f0d905 and < 6967dd944be2a71eddab3a2ae1a1a4dd9e5f8eed
- affected>= 893ae97214c385be02f8ec097298cc48c7f0d905 and < e9c5b03208507dd6d58b0c23a2c60b5c2f4c1b11
- affected>= 893ae97214c385be02f8ec097298cc48c7f0d905 and < 54535692bec9ef464adc714108eb19e49e38b5a2
- affected>= 893ae97214c385be02f8ec097298cc48c7f0d905 and < c73b8795b45f4ad5a95120d2e9b435ea4616e08e
- affected>= 893ae97214c385be02f8ec097298cc48c7f0d905 and < 59da37fee81a8d76079313348ca13c5bc90dd6ae
- affected>= 893ae97214c385be02f8ec097298cc48c7f0d905 and < 8cdcf3d2caacdee7ddd363705fb4d93b0c1a0915
- affected5.14
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.