CVE-2026-23042

Source
https://cve.org/CVERecord?id=CVE-2026-23042
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23042.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23042
Downstream
Related
Published
2026-02-04T16:00:25Z
Modified
2026-08-12T03:30:49Z
Summary
idpf: fix aux device unplugging when rdma is not supported by vport
Details

In the Linux kernel, the following vulnerability has been resolved:

idpf: fix aux device unplugging when rdma is not supported by vport

If vport flags do not contain VIRTCHNL2_VPORT_ENABLE_RDMA, driver does not allocate vdev_info for this vport. This leads to kernel NULL pointer dereference in idpf_idc_vport_dev_down(), which references vdev_info for every vport regardless.

Check, if vdev_info was ever allocated before unplugging aux device.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23042.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
be91128c579c86d295da4325f6ac4710e4e6d2b4
Fixed
0ad6d6e50e9d8bf596cfe77a882ddc20b29f525a
Fixed
4648fb2f2e7210c53b85220ee07d42d1e4bae3f9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23042.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.17.0
Fixed
6.18.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23042.json"