PT-2026-8168 · Linux+2 · Linux Kernel+2

Published

2026-01-01

·

Updated

2026-05-22

·

CVE-2026-23173

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.18.0 #156
Description The Linux kernel contained a flaw in the net/mlx5e module related to Traffic Control (TC) steering flows. Specifically, the issue occurred during the deletion of TC steering flows, where the process did not restrict iteration to existing peers. This resulted in attempts to access non-existent peers, leading to a kernel NULL pointer dereference and a potential system crash. The issue was identified as a BUG: kernel NULL pointer dereference.
Recommendations Update to version 6.18.0 #156 or later to resolve this issue.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-23173
OESA-2026-1760
OPENSUSE-SU-2026:20416-1
SUSE-SU-2026:0962-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21284-1
USN-8278-1
USN-8289-1
USN-8296-1

Affected Products

Linux Kernel
Ubuntu
Mlx5E