cbcvebase.
CVE-2026-23054
published 2026-02-04

CVE-2026-23054: In the Linux kernel, the following vulnerability has been resolved: net: hv_netvsc: reject RSS hash key programming without RX indirection table RSS…

PriorityP421high7.8
EPSS
0.17%
6.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net: hv_netvsc: reject RSS hash key programming without RX indirection table RSS configuration requires a valid RX indirection table. When the device reports a single receive queue, rndis_filter_device_add() does not allocate an indirection table, accepting RSS hash key updates in this state leads to a hang. Fix this by gating netvsc_set_rxfh() on ndc->rx_table_sz and return -EOPNOTSUPP when the table is absent. This aligns set_rxfh with the device capabilities and prevents incorrect behavior.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 < 8288136f508e78eb3563e7073975999cf225a2f98288136f508e78eb3563e7073975999cf225a2f9
linuxlinux>= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 < 82c9039c8ebb715753a40434df714f865a3aec9c82c9039c8ebb715753a40434df714f865a3aec9c
linuxlinux>= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 < 4cd55c609e85ae2313248ef1a33619a3eef44a164cd55c609e85ae2313248ef1a33619a3eef44a16
linuxlinux>= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 < 11dd9a9ef4dc4507a15a69b8511a0013c6c28fa311dd9a9ef4dc4507a15a69b8511a0013c6c28fa3
linuxlinux>= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 < d23564955811da493f34412d7de60fa268c8cb50d23564955811da493f34412d7de60fa268c8cb50
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 4.11.0 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13.0 < 6.18.76.18.7
linuxlinux_kernel>= 6.2.0 < 6.6.1226.6.122
linuxlinux_kernel>= 6.7.0 < 6.12.676.12.67
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8
ubuntulinux-azure-fde-6.17
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp

CVSS provenance

vendor_ubuntu7.8HIGH
vendor_redhat7.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.