SB20260406113 - Out-of-bounds read in Linux kernel freescale dpaa2 driver
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-23422)
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds access in the dpaa2-switch IRQ handler when handling a bad if_id value. A local attacker can trigger an out-of-bounds if_id condition to cause a denial of service.
If an out-of-bounds if_id is detected, the interrupt status is not cleared, which may result in an interrupt storm.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/00f42ace446f1e4bf84988f2281131f52cd32796
- https://git.kernel.org/stable/c/28fd8ac1d49389cb230d712116f54e27ebec11b8
- https://git.kernel.org/stable/c/74badb9c20b1a9c02a95c735c6d3cd6121679c93
- https://git.kernel.org/stable/c/b5bababe7703a7322bc59b803ab1587887a2a5e4
- https://git.kernel.org/stable/c/c7becfe3e604d138bd53b8ac3111b2b3e8ec6b0e
- https://git.kernel.org/stable/c/fa4412cdc5178a48799bafcb8af28fd2fbf3d703