SB2026040694 - Race condition in Linux kernel core en_accel driver
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition (CVE-ID: CVE-2026-23441)
The vulnerability allows a local user to cause unexpected behavior and incorrect results.
The vulnerability exists due to a race condition in the IPSec ASO context handling in the mlx5e driver when processing concurrent IPSec offload ASO operations. A local user can trigger concurrent query or update operations to cause unexpected behavior and incorrect results.
The issue arises because a shared DMA-mapped context is used for ASO operations and can be overwritten before earlier hardware processing completes.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2c6a5be0aee5a44066f68a332c30650900e32ad4
- https://git.kernel.org/stable/c/6834d196107d5267dcad31b44211da7698e8f618
- https://git.kernel.org/stable/c/99aaee927800ea00b441b607737f9f67b1899755
- https://git.kernel.org/stable/c/99b36850d881e2d65912b2520a1c80d0fcc9429a
- https://git.kernel.org/stable/c/c3db55dc0f3344b62da25b025a8396d78763b5fa