CVE-2026-52978
Description
In the Linux kernel, the following vulnerability has been resolved:
net: psp: require admin permission for dev-set and key-rotate
The dev-set and key-rotate netlink operations modify shared device
state (PSP version configuration and cryptographic key material,
respectively) but do not require CAP_NET_ADMIN. The only access
control is psp_dev_check_access() which merely verifies netns
membership.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Linux | Linux | — | 00c94ca2b99e6610e483f92e531b319eeaed94aa < aa1a08a4632af5d1117779e7ff0e32e3c69f29bd, 00c94ca2b99e6610e483f92e531b319eeaed94aa < fb88a8c86109edb15971481e3de816a8bfdfe571, 00c94ca2b99e6610e483f92e531b319eeaed94aa < b718342a7fbaa2dff5fefc31988c07af8c6cbc21 |
| Linux | Linux | — | 6.18, 0 < 6.18, 6.18.33 ≤ 6.18.*, 7.0.10 ≤ 7.0.* … |
References (3)