CVE-2026-23165
published 2026-02-14CVE-2026-23165: In the Linux kernel, the following vulnerability has been resolved: sfc: fix deadlock in RSS config read Since cited commit, core locks the net_device's…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.08%
0.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
sfc: fix deadlock in RSS config read
Since cited commit, core locks the net_device's rss_lock when handling
ethtool -x command, so driver's implementation should not lock it
again. Remove the latter.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.18.9-1 (forky) | linux 6.18.9-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 040cef30b5e67271e3193e0206f82b206fc97095 < 590c8179ffb01c17644181408821b55b8704c50c | 590c8179ffb01c17644181408821b55b8704c50c |
| linux | linux | >= 040cef30b5e67271e3193e0206f82b206fc97095 < 944c614b0a7afa5b87612c3fb557b95a50ad654c | 944c614b0a7afa5b87612c3fb557b95a50ad654c |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.18.9-1 | 6.18.9-1 |
| linux | linux_kernel | >= 6.17 < 6.18.9 | 6.18.9 |
| ubuntu | linux-azure-6.17 | — | — |
| ubuntu | linux-azure-fde-6.17 | — | — |
| ubuntu | linux-gcp-6.17 | — | — |
| ubuntu | linux-oem-6.17 | — | — |
| ubuntu | linux-oracle-6.17 | — | — |
| ubuntu | linux-realtime-6.17 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.18.8 sfc net_device deadlock (Nessus ID 299238 / WID-SEC-2026-0421)
vuldb·2026-04-13·CVSS 5.5
CVE-2026-23165 [MEDIUM] Linux Kernel up to 6.18.8 sfc net_device deadlock (Nessus ID 299238 / WID-SEC-2026-0421)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.18.8. The affected element is the function net_device of the component sfc. Performing a manipulation results in deadlock.
This vulnerability is identified as CVE-2026-23165. The attack can only be performed from the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-9vc4-746x-p2rf: In the Linux kernel, the following vulnerability has been resolved:
sfc: fix deadlock in RSS config read
Since cited commit, core locks the net_devi
ghsa_unreviewed·2026-02-14
CVE-2026-23165 [MEDIUM] CWE-667 GHSA-9vc4-746x-p2rf: In the Linux kernel, the following vulnerability has been resolved:
sfc: fix deadlock in RSS config read
Since cited commit, core locks the net_devi
In the Linux kernel, the following vulnerability has been resolved:
sfc: fix deadlock in RSS config read
Since cited commit, core locks the net_device's rss_lock when handling
ethtool -x command, so driver's implementation should not lock it
again. Remove the latter.
OSV
CVE-2026-23165: In the Linux kernel, the following vulnerability has been resolved: sfc: fix deadlock in RSS config read Since cited commit, core locks the net_device
osv·2026-02-14·CVSS 5.5
CVE-2026-23165 [MEDIUM] CVE-2026-23165: In the Linux kernel, the following vulnerability has been resolved: sfc: fix deadlock in RSS config read Since cited commit, core locks the net_device
In the Linux kernel, the following vulnerability has been resolved: sfc: fix deadlock in RSS config read Since cited commit, core locks the net_device's rss_lock when handling ethtool -x command, so driver's implementation should not lock it again. Remove the latter.
Ubuntu
Linux kernel (Oracle) vulnerabilities
vendor_ubuntu·2026-07-28
CVE-2026-23057 Linux kernel (Oracle) vulnerabilities
Title: Linux kernel (Oracle) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Drivers core;
- Null block device driver;
- Bluetooth drivers;
- Counter interface drivers;
- DMA engine subsystem;
- DPLL subsystem;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO ADC drivers;
- IIO subsystem;
- On-Chip Interconnect management framework;
- IOMMU subsystem;
- IRQ chip drivers;
- Modular ISDN driver;
- LED subsystem;
- Multiple devices driver;
- UACCE accelerator framework;
- MMC subsystem
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2026-07-24
CVE-2026-23057 Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Drivers core;
- Null block device driver;
- Bluetooth drivers;
- Counter interface drivers;
- DMA engine subsystem;
- DPLL subsystem;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO ADC drivers;
- IIO subsystem;
- InfiniBand drivers;
- On-Chip Interconnect management framework;
- IOMMU subsystem;
- IRQ chip drivers;
- Modular ISDN driver;
- LED subsystem;
- Multiple devices driver;
- UA
Ubuntu
Linux kernel (Azure CVM) vulnerabilities
vendor_ubuntu·2026-07-24
CVE-2025-71190 Linux kernel (Azure CVM) vulnerabilities
Title: Linux kernel (Azure CVM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Drivers core;
- Null block device driver;
- Bluetooth drivers;
- Counter interface drivers;
- DMA engine subsystem;
- DPLL subsystem;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO ADC drivers;
- IIO subsystem;
- InfiniBand drivers;
- On-Chip Interconnect management framework;
- IOMMU subsystem;
- IRQ chip drivers;
- Modular ISDN driver;
- LED subsystem;
- Multiple devices driver;
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2026-07-23
CVE-2025-71190 Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Drivers core;
- Null block device driver;
- Bluetooth drivers;
- Counter interface drivers;
- DMA engine subsystem;
- DPLL subsystem;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO ADC drivers;
- IIO subsystem;
- On-Chip Interconnect management framework;
- IOMMU subsystem;
- IRQ chip drivers;
- Modular ISDN driver;
- LED subsystem;
- Multiple devices driver;
- UACCE accelerator framework;
- MMC subsystem;
-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-20
CVE-2025-71190 Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Drivers core;
- Null block device driver;
- Bluetooth drivers;
- Counter interface drivers;
- DMA engine subsystem;
- DPLL subsystem;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO ADC drivers;
- IIO subsystem;
- On-Chip Interconnect management framework;
- IOMMU subsystem;
- IRQ chip drivers;
- Modular ISDN driver;
- LED subsystem;
- Multiple devices driver;
- UACCE accelerator framework;
- MMC subsystem;
- Ether
Red Hat
kernel: sfc: fix deadlock in RSS config read
vendor_redhat·2026-02-14·CVSS 5.5
CVE-2026-23165 [MEDIUM] CWE-764 kernel: sfc: fix deadlock in RSS config read
kernel: sfc: fix deadlock in RSS config read
In the Linux kernel, the following vulnerability has been resolved:
sfc: fix deadlock in RSS config read
Since cited commit, core locks the net_device's rss_lock when handling
ethtool -x command, so driver's implementation should not lock it
again. Remove the latter.
A deadlock vulnerability was found in the Solarflare (sfc) network driver. When reading RSS configuration via ethtool -x, the driver attempts to acquire the rss_lock that is already held by the networking core, causing a deadlock and system hang.
Statement: This deadlock affects systems with Solarflare NICs when querying RSS settings via ethtool. Any local user with access to network configuration can trigger the hang. The fix is straightforward — remove the redundant lock acquis
Debian
CVE-2026-23165: linux - In the Linux kernel, the following vulnerability has been resolved: sfc: fix de...
vendor_debian·2026·CVSS 5.5
CVE-2026-23165 [MEDIUM] CVE-2026-23165: linux - In the Linux kernel, the following vulnerability has been resolved: sfc: fix de...
In the Linux kernel, the following vulnerability has been resolved: sfc: fix deadlock in RSS config read Since cited commit, core locks the net_device's rss_lock when handling ethtool -x command, so driver's implementation should not lock it again. Remove the latter.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.18.9-1)
sid: resolved (fixed in 6.18.9-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
2026-02-14
Published