PT-2026-72238 · Linux · Linux Kernel
CVE-2026-72049
·
Published
2026-08-15
·
Updated
2026-08-18
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the legacy IEEE802154 NL family operations table within
net/ieee802154/netlink.c. The LLSEC dump entries, specifically LLSEC LIST KEY, LLSEC LIST DEV, LLSEC LIST DEVKEY, and LLSEC LIST SECLEVEL, are implemented using the IEEE802154 DUMP() function, which does not set any permission flags. Consequently, these operations are executed without administrative gating. A local user with the ability to open AF NETLINK or NETLINK GENERIC can resolve the 802.15.4 MAC family and trigger an LLSEC LIST KEY dump on any wpan netdev with an installed LLSEC key. This allows the user to retrieve the raw 16-byte AES-128 key via the IEEE802154 ATTR LLSEC KEY BYTES attribute, compromising the confidentiality and authenticity of the 802.15.4 LLSEC link, as the same key is used for both authentication and encryption via CCM*.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel