SB20260816194 - Deadlock in Linux kernel qlogic qede driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Deadlock (CVE-ID: CVE-2026-74523)
CWE-ID: CWE-833 - Deadlock
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a deadlock in the qede recovery path when handling a TX timeout on a qede NIC with VXLAN/GENEVE tunnel ports configured. A local attacker can trigger a TX timeout condition to cause a denial of service.
The issue can wedge the rtnetlink control plane of the whole machine while the node may still answer ping.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/451c9075d6c53f2438d110addbeeeea6fac18567
- https://git.kernel.org/stable/c/4626df3f63c9185efba5750fe76ac01ab3351bae
- https://git.kernel.org/stable/c/6f1ef8170d3d8ad9319aa01347945dcdf5cc4f27
- https://git.kernel.org/stable/c/e382a4efeeae6555b95d9ff336cf3094ee7d336b
- https://git.kernel.org/stable/c/e51becb8f3377a377171ed5bf0082b96e22e6292