PT-2026-8168 · Mlx5E+3 · Mlx5E+3

CVE-2026-23173

·

Published

2026-01-01

·

Updated

2026-08-21

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.18.0 #156
Description The Linux kernel contained a flaw in the net/mlx5e module related to Traffic Control (TC) steering flows. Specifically, the issue occurred during the deletion of TC steering flows, where the process did not restrict iteration to existing peers. This resulted in attempts to access non-existent peers, leading to a kernel NULL pointer dereference and a potential system crash. The issue was identified as a BUG: kernel NULL pointer dereference.
Recommendations Update to version 6.18.0 #156 or later to resolve this issue.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-77742
BDU:2026-11812
CVE-2026-23173
OESA-2026-1760
OESA-2026-1832
OESA-2026-1833
OPENSUSE-SU-2026:20416-1
SUSE-SU-2026:0962-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20873-1
SUSE-SU-2026:20876-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21284-1
USN-8278-1
USN-8278-2
USN-8289-1
USN-8289-2
USN-8296-1
USN-8296-2
USN-8393-1
USN-8440-1
USN-8499-1
USN-8570-1
USN-8570-2
USN-8594-1
USN-8604-1
USN-8605-1
USN-8669-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu
Mlx5E