CVE Database
/

CVE-2026-23013

Back to search

CVE-2026-23013

Published: Jan 25, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

7.0

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: net: octeon_ep_vf: fix free_irq dev_id mismatch in IRQ rollback octep_vf_request_irqs() requests MSI-X queue IRQs with dev_id set to ioq_vector. If request_irq() fails part-way, the rollback loop calls free_irq() with dev_id set to 'oct', which does not match the original dev_id and may leave the irqaction registered. This can keep IRQ handlers alive while ioq_vector is later freed during unwind/teardown, leading to a use-after-free or crash when an interrupt fires. Fix the error path to free IRQs with the same ioq_vector dev_id used during request_irq().

VendorProductVersions

Linux

Linux

affected
1cd3b407977c3ab1d2ddc26cb7113e7fb1509cd1 - < aa05a8371ae4a452df623f7202c72409d3c50e40
affected
1cd3b407977c3ab1d2ddc26cb7113e7fb1509cd1 - < aa4c066229b05fc3d3c5f42693d25b1828533b6e
affected
1cd3b407977c3ab1d2ddc26cb7113e7fb1509cd1 - < f93fc5d12d69012788f82151bee55fce937e1432

Linux

Linux

affected
6.9
unaffected
0 - < 6.9
unaffected
6.12.67 - <= 6.12.*
unaffected
6.18.7 - <= 6.18.*
unaffected
6.19 - <= *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

High

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now