SB20260928233 - Incomplete cleanup in Linux kernel octeontx2 nic driver



SB20260928233 - Incomplete cleanup in Linux kernel octeontx2 nic driver

Published: September 28, 2026 Updated: September 30, 2026

Security Bulletin ID SB20260928233
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incomplete cleanup (CVE-ID: CVE-2026-97966)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to affect scheduler topology settings for later queue allocations.

The vulnerability exists due to incomplete cleanup of scheduler topology state in the OcteonTX2 PF QoS scheduler queue teardown logic when freeing QoS-allocated scheduler queues. A local user can trigger QoS scheduler hierarchy teardown to affect scheduler topology settings for later queue allocations.

PRIO_ANCHOR and RR_PRIO settings can persist in the shared scheduler pool.


Remediation

Install update from vendor's website.