CVE-2026-52978

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/06/2026
Last modified:
14/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: psp: require admin permission for dev-set and key-rotate<br /> <br /> The dev-set and key-rotate netlink operations modify shared device<br /> state (PSP version configuration and cryptographic key material,<br /> respectively) but do not require CAP_NET_ADMIN. The only access<br /> control is psp_dev_check_access() which merely verifies netns<br /> membership.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.18 (including) 6.18.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.10 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*