CVE-2026-72127: netdev-genl: report NAPI thread PID in the caller's pid namespace
In the Linux kernel, the following vulnerability has been resolved:
netdev-genl: report NAPI thread PID in the caller's pid namespace
netdevnlnapifillone() reports the NAPI kthread PID in NETDEVANAPIPID using taskpidnr(), which returns the PID in the initial pid namespace.
NETDEVCMDNAPIGET does not have GENLADMINPERM and the netdev genl family is netnsok, so a caller in a child pid namespace can issue it. That caller then sees the kthread's global PID, even though the kthread is not visible in its pid namespace, where the value should be 0.
Translate the PID through the caller's pid namespace, the same way commit 3799c2570982 ("iouring/fdinfo: translate SqThread PID through caller's pidns") did for the iouring SQPOLL thread. The doit and dumpit paths both run synchronously in the caller's context, so taskactivepidns(current) is the caller's pid namespace.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72127?
CVE-2026-72127 has a severity rating of 9, indicating a critical risk.
How do I fix CVE-2026-72127?
To fix CVE-2026-72127, update your Linux kernel to the latest version where this vulnerability is patched.
What does CVE-2026-72127 affect?
CVE-2026-72127 affects the Linux kernel's netdev-genl component, which handles network device notifications.
What is the impact of CVE-2026-72127?
The impact of CVE-2026-72127 can lead to incorrect reporting of NAPI thread PIDs, potentially affecting network operations.
When was CVE-2026-72127 published?
CVE-2026-72127 was published on August 15, 2026.