CVE-2026-23206

Description

From CVE.org

In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: prevent ZERO_SIZE_PTR dereference when num_ifs is zero The driver allocates arrays for ports, FDBs, and filter blocks using kcalloc() with ethsw->sw_attr.num_ifs as the element count. When the device reports zero interfaces (either due to hardware configuration or firmware issues), kcalloc(0, ...) returns ZERO_SIZE_PTR (0x10) instead of NULL. Later in dpaa2_switch_probe(), the NAPI initialization unconditionally accesses ethsw->ports[0]->netdev, which attempts to dereference ZERO_SIZE_PTR (address 0x10), resulting in a kernel panic. Add a check to ensure num_ifs is greater than zero after retrieving device attributes. This prevents the zero-sized allocations and subsequent invalid pointer dereference.

Statement

A denial of service issue exists in the dpaa2 switch driver when the device reports zero interfaces. The driver allocates several per interface arrays using kcalloc with ethsw sw_attr num_ifs as the element count. When num_ifs is 0 kcalloc may return ZERO_SIZE_PTR 0x10 instead of NULL. Later during probe the initialization path assumes at least one port exists and unconditionally accesses ethsw ports 0 netdev. If ports points to ZERO_SIZE_PTR this becomes an invalid pointer dereference at address 0x10 which triggers a kernel panic. The vulnerable condition can be reached during device initialization when hardware configuration or firmware reports an unexpected attribute set. Exploitation is typically local because it requires the presence of a dpaa2 switch device and driver probe. No special privileges are required beyond being able to trigger driver loading, for example via automatic module loading on systems where this hardware is present. The primary impact is availability loss. For the CVSS the PR:N metric is used because the attacker does not need elevated permissions inside the kernel. The attack surface is local rather than network because the condition occurs in probe before normal datapath operations.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.25.5N/A
Attack VectorLocalLocalN/A
Attack ComplexityLowLowN/A
Privileges RequiredNoneLowN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityNoneNoneN/A
Integrity ImpactNoneNoneN/A
Availability ImpactHighHighN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Integrity,Confidentiality,Availability

Technical Impact: Modify Application Data; Execute Unauthorized Code or Commands

An attacker could modify the structure of the message or data being sent to the downstream component, possibly injecting commands.

Availability

Technical Impact: DoS: Resource Consumption (Other)

in some contexts, a negative value could lead to resource consumption.

Confidentiality,Integrity

Technical Impact: Modify Memory; Read Memory

If a negative value is used to access memory, buffers, or other indexable structures, it could access memory outside the bounds of the buffer.

Frequently Asked Questions

Want to get errata notifications? Sign up here.