Description
In the Linux kernel, the following vulnerability has been resolved:

octeontx2-pf: fix NULL deref of af_xdp_zc_qidx on rep setup

af_xdp_zc_qidx tracks receive queues using AF_XDP zero-copy and is
allocated during PF/VF probe. Representors and other non-AF_XDP paths
leave the pointer NULL, but several call sites used test_bit() on it
unconditionally.

Switching to devlink eswitch mode creates representors and runs
otx2_init_hw_resources(), which reaches otx2_pool_aq_init() and oopses
when dereferencing the NULL bitmap. Add NULL checks before every
af_xdp_zc_qidx test_bit() use in the RSS, ethtool, XSK, and pool init
paths.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Kernel Panic
Action: Immediate Patch
AI Analysis

Impact

The octeontx2-pf driver contains a NULL pointer dereference where the af_xdp_zc_qidx bitmap is accessed without a NULL check. This bug is triggered during representor initialization in devlink eswitch mode and can cause an oops leading to a kernel panic. The resulting system downtime is the only documented impact; no privilege escalation or information disclosure is referenced in the CVE description. The weakness corresponds to a missing null‑check before bitmap operations (CWE‑476).

Affected Systems

The vulnerability exists on any Linux kernel that runs on an OcteonTX2 SoC before the fix commit 7e33c6bd049b532d2ec4916895ef07e538bed905 is incorporated. It applies to all Linux variants deployed on OcteonTX2 hardware, regardless of vendor, since the kernel source code is the same. Systems using a newer kernel that includes the patch are no longer affected.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in CISA KEV, indicating an extremely low probability of active exploitation. Based on the description, it is inferred that the attack vector would require local access to enable devlink eswitch mode or trigger representor initialization, which results in a kernel panic that causes a high impact denial of service. No publicly known exploits exist at present, so the primary risk is the potential for accidental system crashes during normal operation. Nevertheless, the high severity of the kernel crash warrants patching when available.

Generated by OpenCVE AI on September 20, 2026 at 04:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes commit 7e33c6bd049b532d2ec4916895ef07e538bed905, which adds NULL checks before accessing af_xdp_zc_qidx.
  • Reboot the system after applying the patch to ensure the kernel starts with the corrected code.
  • If a kernel update cannot be applied immediately, disable devlink eswitch mode or AF_XDP usage on representors until the patched kernel is available.

Generated by OpenCVE AI on September 20, 2026 at 04:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix NULL deref of af_xdp_zc_qidx on rep setup af_xdp_zc_qidx tracks receive queues using AF_XDP zero-copy and is allocated during PF/VF probe. Representors and other non-AF_XDP paths leave the pointer NULL, but several call sites used test_bit() on it unconditionally. Switching to devlink eswitch mode creates representors and runs otx2_init_hw_resources(), which reaches otx2_pool_aq_init() and oopses when dereferencing the NULL bitmap. Add NULL checks before every af_xdp_zc_qidx test_bit() use in the RSS, ethtool, XSK, and pool init paths.
Title octeontx2-pf: fix NULL deref of af_xdp_zc_qidx on rep setup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:58.199Z

Reserved: 2026-09-11T19:38:34.785Z

Link: CVE-2026-90080

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:57.317

Modified: 2026-09-17T17:16:57.317

Link: CVE-2026-90080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses