SB20260325169 - Improper Resource Shutdown or Release in Linux kernel ethernet mediatek driver
Published: March 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Resource Shutdown or Release (CVE-ID: CVE-2026-23284)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in the mtk_eth_soc driver when handling eBPF program setup errors. A local user can trigger the mtk_open routine failure in mtk_xdp_setup() to cause a denial of service.
Successful exploitation may lead to system crash or network interface disruption.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0abc73c8a40fd64ac1739c90bb4f42c418d27a5e
- https://git.kernel.org/stable/c/29629dd7d37349e9fb605375a75de44ac8926ea9
- https://git.kernel.org/stable/c/6f95b59520278a72df9905db791b7ea31375fbc1
- https://git.kernel.org/stable/c/8c2d76a9658a4dbfcf02f2693a97e2d5ff42197a
- https://git.kernel.org/stable/c/b73dfe1ea7be7a072482434643b517d7726f4c8d
- https://git.kernel.org/stable/c/ff14cd44c85c20ad69479db73698185de291550c