cbcvebase.
CVE-2026-23206
published 2026-02-14

CVE-2026-23206: In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: prevent ZERO_SIZE_PTR dereference when num_ifs is zero The driver allocates…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: prevent ZERO_SIZE_PTR dereference when num_ifs is zero The driver allocates arrays for ports, FDBs, and filter blocks using kcalloc() with ethsw->sw_attr.num_ifs as the element count. When the device reports zero interfaces (either due to hardware configuration or firmware issues), kcalloc(0, ...) returns ZERO_SIZE_PTR (0x10) instead of NULL. Later in dpaa2_switch_probe(), the NAPI initialization unconditionally accesses ethsw->ports[0]->netdev, which attempts to dereference ZERO_SIZE_PTR (address 0x10), resulting in a kernel panic. Add a check to ensure num_ifs is greater than zero after retrieving device attributes. This prevents the zero-sized allocations and subsequent invalid pointer dereference.

Affected

58 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 0b1b71370458860579831e77485883fcf2e8fbbe < 2fcccca88456b592bd668db13aa1d29ed257ca2b2fcccca88456b592bd668db13aa1d29ed257ca2b
linuxlinux>= 0b1b71370458860579831e77485883fcf2e8fbbe < 80165ff16051448d6f840585ebe13f2400415df380165ff16051448d6f840585ebe13f2400415df3
linuxlinux>= 0b1b71370458860579831e77485883fcf2e8fbbe < b97415c4362f739e25ec6f71012277086fabdf6fb97415c4362f739e25ec6f71012277086fabdf6f
linuxlinux>= 0b1b71370458860579831e77485883fcf2e8fbbe < 4acc40db06ffd0fd92683505342b00c8a7394c604acc40db06ffd0fd92683505342b00c8a7394c60
linuxlinux>= 0b1b71370458860579831e77485883fcf2e8fbbe < 155eb99aff2920153bf21217ae29565fff81e6af155eb99aff2920153bf21217ae29565fff81e6af
linuxlinux>= 0b1b71370458860579831e77485883fcf2e8fbbe < ed48a84a72fefb20a82dd90a7caa7807e90c6f66ed48a84a72fefb20a82dd90a7caa7807e90c6f66
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 5.13 < 5.15.2005.15.200
linuxlinux_kernel>= 5.16 < 6.1.1636.1.163
linuxlinux_kernel>= 6.13 < 6.18.106.18.10
linuxlinux_kernel>= 6.2 < 6.6.1246.6.124
linuxlinux_kernel>= 6.7 < 6.12.706.12.70
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.