Impact
The flaw originates from an incorrect check that determines whether any logical functions (LFs) have been assigned to a physical or virtual function on octeontx2 devices. The erroneous condition allows a user with devlink command privileges to set the maximum number of LFs before any LFs are assigned, which can lead to resource misconfiguration or kernel instability. The weakness is a classic example of improper input validation (CWE‑20) and could ultimately result in a kernel crash or denial of service.
Affected Systems
All Linux kernel builds that include the octeontx2 driver without the new patch are affected. The issue covers generic Linux kernel deployments, as indicated by the vendor/product list "Linux:Linux".
Risk and Exploitability
The CVSS score is not provided and EPSS data is unavailable, so the precise quantitative risk cannot be determined. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to run devlink commands with sufficient privileges, limiting the threat to privileged users or compromised systems. However, because the flaw could trigger a kernel crash, the potential impact if exploited can be severe. Applying the patch removes the risk, so systems updated to the latest kernel version are no longer vulnerable.
OpenCVE Enrichment