Description
In the Linux kernel, the following vulnerability has been resolved:

octeontx2-af: fix NULL deref in NIX TM tree debugfs read path

rvu_dbg_nix_tm_tree_display() dereferences pfvf->sq_ctx without
checking whether the SQ context has been allocated. Reading
/sys/kernel/debug/octeontx2/nix/tm_tree for a NIX LF whose transmit
queues are not set up triggers a kernel oops.

Guard the read path the same way rvu_dbg_nix_tm_tree_write() already
does and return -EINVAL with a seq_file message when sq_ctx is NULL.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The kernel bug causes a null pointer dereference when reading the NIX TM tree via /sys/kernel/debug/octeontx2/nix/tm_tree if the transmit‑queue context is not allocated. This leads to a kernel oops that silently crashes the system. The weakness is a null dereference (CWE‑476) and the result is a local denial of service. No remote code execution or privilege escalation is reported.

Affected Systems

The flaw is present in the Linux kernel's octeontx2-af driver, which is used by all Linux distributions that ship the octeontx2 driver for the Chelsio/TX family of accelerators. The vendor data lists Linux:Linux and the CPE covers the entire Linux kernel. No specific kernel version is listed, so any kernel build that includes this driver before the fix is affected.

Risk and Exploitability

The CVSS score is not shown in the advisory, but the EPSS score is very low, indicating that widespread exploitation is unlikely. The debugfs file is typically accessible only to root or kernel module users, so the attack vector is local. The vulnerability is not listed in the CISA KEV catalog, so there are no documented active exploits. The risk level is moderate but should be mitigated promptly to avoid accidental system crashes.

Generated by OpenCVE AI on September 20, 2026 at 03:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that fixes the null dereference in octeontx2-af, such as the commit identified in the advisory
  • If updating the kernel is not possible immediately, change the permissions or ownership of /sys/kernel/debug/octeontx2/nix/tm_tree to prevent unprivileged access, or remove the debugfs entry altogether
  • Ensure that all NIX transmit queues are properly allocated before enabling the driver; review device configuration scripts to avoid use without initialization

Generated by OpenCVE AI on September 20, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix NULL deref in NIX TM tree debugfs read path rvu_dbg_nix_tm_tree_display() dereferences pfvf->sq_ctx without checking whether the SQ context has been allocated. Reading /sys/kernel/debug/octeontx2/nix/tm_tree for a NIX LF whose transmit queues are not set up triggers a kernel oops. Guard the read path the same way rvu_dbg_nix_tm_tree_write() already does and return -EINVAL with a seq_file message when sq_ctx is NULL.
Title octeontx2-af: fix NULL deref in NIX TM tree debugfs read path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:01.525Z

Reserved: 2026-09-11T19:38:34.785Z

Link: CVE-2026-90085

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:57.957

Modified: 2026-09-17T17:16:57.957

Link: CVE-2026-90085

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:30:13Z

Weaknesses