Home

Description

In the Linux kernel, the following vulnerability has been resolved: net: octeon_ep_vf: fix free_irq dev_id mismatch in IRQ rollback octep_vf_request_irqs() requests MSI-X queue IRQs with dev_id set to ioq_vector. If request_irq() fails part-way, the rollback loop calls free_irq() with dev_id set to 'oct', which does not match the original dev_id and may leave the irqaction registered. This can keep IRQ handlers alive while ioq_vector is later freed during unwind/teardown, leading to a use-after-free or crash when an interrupt fires. Fix the error path to free IRQs with the same ioq_vector dev_id used during request_irq().

PUBLISHED Reserved 2026-01-13 | Published 2026-01-25 | Updated 2026-01-25 | Assigner Linux

Product status

Default status
unaffected

1cd3b407977c3ab1d2ddc26cb7113e7fb1509cd1 (git) before aa05a8371ae4a452df623f7202c72409d3c50e40
affected

1cd3b407977c3ab1d2ddc26cb7113e7fb1509cd1 (git) before aa4c066229b05fc3d3c5f42693d25b1828533b6e
affected

1cd3b407977c3ab1d2ddc26cb7113e7fb1509cd1 (git) before f93fc5d12d69012788f82151bee55fce937e1432
affected

Default status
affected

6.9
affected

Any version before 6.9
unaffected

6.12.67 (semver)
unaffected

6.18.7 (semver)
unaffected

6.19-rc6 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/aa05a8371ae4a452df623f7202c72409d3c50e40

git.kernel.org/...c/aa4c066229b05fc3d3c5f42693d25b1828533b6e

git.kernel.org/...c/f93fc5d12d69012788f82151bee55fce937e1432

cve.org (CVE-2026-23013)

nvd.nist.gov (CVE-2026-23013)

Download JSON