Back to overview

CVE-2026-52978

Description
In the Linux kernel, the following vulnerability has been resolved: net: psp: require admin permission for dev-set and key-rotate The dev-set and key-rotate netlink operations modify shared device state (PSP version configuration and cryptographic key material, respectively) but do not require CAP_NET_ADMIN. The only access control is psp_dev_check_access() which merely verifies netns membership.

Metadata

CVE ID
CVE-2026-52978
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-24 16:28 UTC
Last updated
2026-06-24 16:28 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 00c94ca2b99e6610e483f92e531b319eeaed94aa < aa1a08a4632af5d1117779e7ff0e32e3c69f29bd, 00c94ca2b99e6610e483f92e531b319eeaed94aa < fb88a8c86109edb15971481e3de816a8bfdfe571, 00c94ca2b99e6610e483f92e531b319eeaed94aa < b718342a7fbaa2dff5fefc31988c07af8c6cbc21
Linux Linux 6.18, 0 < 6.18, 6.18.33 ≤ 6.18.*, 7.0.10 ≤ 7.0.* …
Back to overview