Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-72060

Published Aug 15, 2026 EPSS 0.21% (11th pctl)

Overview

CVE-2026-72060 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: ti: icssg: guard PA stat lookups

icssg_ndo_get_stats64() unconditionally calls emac_get_stat_by_name()

with FW PA stat names regardless of whether the PA stats block is

present on the hardware. emac_get_stat_by_name() already guards the

PA stats lookup with `if (emac->prueth->pa_stats)`; when that pointer

is NULL the lookup falls through to netdev_err() and returns -EINVAL.

Because ndo_get_stats64 is polled regularly by the networking stack

this produces thousands of log entries of the form:

icssg-prueth icssg1-eth end0: Invalid stats FW_RX_ERROR

A secondary consequence is that the int(-EINVAL) return value is

implicitly widened to a near-ULLONG_MAX unsigned value when accumulated

into the __u64 fields of rtnl_link_stats64, silently corrupting the

rx_errors, rx_dropped and tx_dropped counters reported by `ip -s link`.

Every other PA-aware code path in the driver is already guarded with

the same `

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-72060?

CVE-2026-72060 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-72060?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-72060?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-72060?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-72060 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.