CVE-2026-23180

HIGH

Linux Kernel 5.15.0-6.18.9 - Out-of-Bounds Read in dpaa2-switch IRQ Handler

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: add bounds check for if_id in IRQ handler The IRQ handler extracts if_id from the upper 16 bits of the hardware status register and uses it to index into ethsw->ports[] without validation. Since if_id can be any 16-bit value (0-65535) but the ports array is only allocated with sw_attr.num_ifs elements, this can lead to an out-of-bounds read potentially. Add a bounds check before accessing the array, consistent with the existing validation in dpaa2_switch_rx().

Scores

CVSS v3 7.0
EPSS 0.0002
EPSS Percentile 4.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (19)
linux/Kernel 5.15.0 - 5.15.200linux
linux/Kernel 5.16.0 - 6.1.163linux
linux/Kernel 6.13.0 - 6.18.10linux
linux/Kernel 6.2.0 - 6.6.124linux
linux/Kernel 6.7.0 - 6.12.70linux
Linux/Linux < 5.15
Linux/Linux 24ab724f8a4661b2dc8e696b41df93bdc108f7a1 - 1b381a638e1851d8cfdfe08ed9cdbec5295b18c9
Linux/Linux 24ab724f8a4661b2dc8e696b41df93bdc108f7a1 - 2447edc367800ba914acf7ddd5d250416b45fb31
Linux/Linux 24ab724f8a4661b2dc8e696b41df93bdc108f7a1 - 31a7a0bbeb006bac2d9c81a2874825025214b6d8
Linux/Linux 24ab724f8a4661b2dc8e696b41df93bdc108f7a1 - 34b56c16efd61325d80bf1d780d0e176be662f59
... and 9 more
Published Feb 14, 2026
Tracked Since Feb 18, 2026