CVE-2026-72297

Published: Ago 15, 2026 Last Modified: Ago 15, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

net: atm: reject out-of-range traffic classes in QoS validation

Reject ATM traffic classes above ATM_ANYCLASS in check_tp().
SO_ATMQOS stores the supplied QoS after check_qos() succeeds, so
accepting larger values leaves invalid traffic_class values in
vcc->qos.

That bad state later reaches pvc_info(), which indexes class_name[]
with vcc->qos.{rx,tp}.traffic_class. Values above ATM_ANYCLASS cause
an out-of-bounds read when /proc/net/atm/pvc is read.

Tighten the existing QoS validation so invalid traffic_class values
are rejected at the point where user supplied QoS is accepted.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0022
Percentile
0,1th
Updated

Single Data Point

Only one EPSS measurement is available for this CVE. Trend analysis requires multiple data points over time.

https://git.kernel.org/stable/c/15444b57fdc6fc3f3e22a87f791ae5be81e6ecf5
https://git.kernel.org/stable/c/1a6dda72455b399ce9c1a12695471dc4d5c61add
https://git.kernel.org/stable/c/2b3e241729e87afed13ac0f666472d5d6ca42e87
https://git.kernel.org/stable/c/367acd288bc6255e247cb1a1efbf5c6567cab423
https://git.kernel.org/stable/c/513f820b3f0cf4462e17d84c39ed3948d061a6ea
https://git.kernel.org/stable/c/806b7b6edc8446e8b94b706807a7090a14d47b5c
https://git.kernel.org/stable/c/cdf19f380e46192e7084be559638aab1f6ed86a2
https://git.kernel.org/stable/c/e62adb157c2eaad9ad4867ec6cd9af5b9a51b1c7