Database/Control plane, storage & DevOps
Linux MACsec (replay protection at XPN lower-PN wrap): MACsec replay protection fails at the extended-packet-number
Impact
MACsec replay protection fails at the extended-packet-number lower-PN wrap. When the packet number is U32_MAX the increment overflows to zero and neither replay branch fires, so next_pn_halves is never advanced — an attacker who captured legitimate ciphertext can replay it and have it accepted. Replay protection is the property that stops a passive observer from becoming an active injector on an encrypted link; losing it turns a tap into a traffic-injection capability on links that carry multiple tenants.
Who can reach it
An attacker who can capture and re-transmit frames on a MACsec-protected link, timed to the PN wrap. Passive tap plus injection capability, no keys required.
What to do
Kernel upgrade plus host reboot on any node terminating software MACsec (switch NOSes based on Linux included, where it arrives as a NOS image update plus reload). No config workaround — you cannot turn replay protection back on if the check itself is broken. Companion Linux MACsec issues in the same window: CVE-2026-72019, CVE-2022-48720.
References
Related entries
- Atlantis: workspace names escape the working directory into os.RemoveAll and os.MkdirAllCVE-2026-64679 · Atlantis (workspace path handling in atlantis.yaml and /api/plan)High
- Dell PowerStore T SDNAS: unauthenticated NFS/RPC buffer overflow allows command execution on the arrayCVE-2026-70415 · Dell PowerStore T SDNAS (NFS/RPC service)High
- Jenkins: inconsistent case handling in user and group names allows impersonation of other accountsCVE-2026-70429 · Jenkins core (user and group name case-sensitivity handling)High
- Apache Airflow FAB provider: Authentik OAuth path does not check id_token issuer or audienceCVE-2026-86466 · Apache Airflow FAB provider (Authentik OAuth id_token validation)High
- Ansible community.general: memcached fact cache unpickles values, giving code execution on the controllerCVE-2026-87874 · Ansible community.general collection (memcached fact cache plugin)High
- GlusterFS (glusterd, auth.allow): The auth.allow option does not actually restrict who may connect, so anyCVE-2018-1112 · GlusterFS (glusterd, auth.allow)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.