Description
In the Linux kernel, the following vulnerability has been resolved:

net: mscc: ocelot: add missing lock protection in ocelot_port_xmit_inj()

ocelot_port_xmit_inj() calls ocelot_can_inject() and
ocelot_port_inject_frame() without holding the injection group lock.
Both functions contain lockdep_assert_held() for the injection lock,
and the correct caller felix_port_deferred_xmit() properly acquires
the lock using ocelot_lock_inj_grp() before calling these functions.

Add ocelot_lock_inj_grp()/ocelot_unlock_inj_grp() around the register
injection path to fix the missing lock protection. The FDMA path is not
affected as it uses its own locking mechanism.
Published: 2026-05-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ocelot driver contained a race condition because ocelot_port_xmit_inj() called ocelot_can_inject() and ocelot_port_inject_frame() without acquiring the injection group lock. These functions enforce a lockdep assertion that the lock should be held. The missing lock protection can lead to concurrent access to shared kernel state, potentially corrupting memory or causing a kernel crash, which translates into a denial of service.

Affected Systems

All Linux kernel releases that contain the ocelot network driver before the patch that adds lock protection around the registration injection path are affected. The issue is tied to the ocelot driver implementation used in kernel versions prior to the inclusion of the missing lock fix.

Risk and Exploitability

The CVSS score of 5.5 indicates a Medium severity, while the EPSS score is <1%, showing an extremely low likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog, indicating that widespread exploitation has not been observed. However, because the flaw involves a race condition in kernel space, the potential impact is severe when an attacker can influence network traffic directed to the affected driver. The likely attack vector is a local or remote attacker who can generate traffic processed by the ocelot driver to trigger the race, causing a kernel crash or data corruption.

Generated by OpenCVE AI on August 14, 2026 at 02:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch adding lock protection in ocelot_port_xmit_inj()
  • If a kernel update is not immediately available, disable the ocelot driver or its injection functionality to reduce exposure until the patch is applied
  • Enable kernel lockdep during testing to detect any remaining locking issues in related code paths

Generated by OpenCVE AI on August 14, 2026 at 02:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8492-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8497-1 Linux kernel (Low Latency) vulnerabilities
Ubuntu USN Ubuntu USN USN-8498-1 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8499-1 Linux kernel (Xilinx) vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-3 Linux kernel (Raspberry Pi Real-time) vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-4 Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-5 Linux kernel (FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8606-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8607-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8609-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8619-1 Linux kernel (HWE) vulnerabilities
History

Thu, 28 May 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-367

Thu, 28 May 2026 12:15:00 +0000


Wed, 27 May 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-367

Wed, 27 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: add missing lock protection in ocelot_port_xmit_inj() ocelot_port_xmit_inj() calls ocelot_can_inject() and ocelot_port_inject_frame() without holding the injection group lock. Both functions contain lockdep_assert_held() for the injection lock, and the correct caller felix_port_deferred_xmit() properly acquires the lock using ocelot_lock_inj_grp() before calling these functions. Add ocelot_lock_inj_grp()/ocelot_unlock_inj_grp() around the register injection path to fix the missing lock protection. The FDMA path is not affected as it uses its own locking mechanism.
Title net: mscc: ocelot: add missing lock protection in ocelot_port_xmit_inj()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-05-27T12:15:15.494Z

Reserved: 2026-05-13T15:03:33.078Z

Link: CVE-2026-45849

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-05-27T14:16:56.850

Modified: 2026-06-25T21:03:35.277

Link: CVE-2026-45849

cve-icon Redhat

Severity :

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-45849 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T02:30:17Z

Weaknesses