{"apiVersion":"1.0","identifier":"CVE-2026-72045","description":"In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF rvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct index into the LMT map table to read another function-s LMTLINE physical base address and copy it into the caller-s own LMT map table entry. The mailbox dispatcher authenticates req->hdr.pcifunc from the IRQ source, but req->base_pcifunc is a separate payload field and is not sanitized. Reject the request with -EPERM when a VF caller-s base_pcifunc is not a valid function under its own PF. is_pf_func_valid() bounds the FUNC field to the PF-s configured VF count, keeping the computed index inside the caller-s own slot block.","publishedAt":"2026-08-15T06:21:13","lastModifiedAt":"2026-08-23T13:16:38","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72045","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","epssProbability":0.00164,"riskScore":0.89,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72045","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72045","en":"https://www.redsauce.net/en/cves/CVE-2026-72045","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72045","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72045","de":"https://www.redsauce.net/de/cves/CVE-2026-72045","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72045","el":"https://www.redsauce.net/el/cves/CVE-2026-72045"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72045"}}