Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-97435
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local privileged user to redirect traffic to an unintended port or trigger an out-of-bounds access.
The vulnerability exists due to improper validation of a destination port index in the SJA1105 flower classifier when configuring a redirect action to a switch port on a different switch chip. A local privileged user can configure a redirect action referencing a port from another switch chip to redirect traffic to an unintended port or trigger an out-of-bounds access.