PT-2026-5538 · Mlx5E+3 · Mlx5E+3
CVE-2026-23035
·
Published
2026-01-01
·
Updated
2026-08-30
CVSS v3.1
5.1
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.18.0-rc5+ #115
Description
The Linux kernel contains a flaw in the mlx5e network driver. Specifically, the
mlx5e priv structure, which is unstable, could be cleared if profile attachment failed. This issue occurs because the netdev pointer was not correctly passed to the mlx5e destroy netdev() function. This could lead to a kernel oops during mlx5e remove when switchdev mode fails due to profile change failures. The issue manifests as a kernel NULL pointer dereference within the mlx5e dcbnl dscp app function.Recommendations
Update to Linux kernel version 6.18.0-rc5+ #115 or a later version to resolve this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu
Mlx5E