{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90080","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.785Z","datePublished":"2026-09-17T16:05:58.199Z","dateUpdated":"2026-09-17T16:05:58.199Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-17T16:05:58.199Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: fix NULL deref of af_xdp_zc_qidx on rep setup\n\naf_xdp_zc_qidx tracks receive queues using AF_XDP zero-copy and is\nallocated during PF/VF probe. Representors and other non-AF_XDP paths\nleave the pointer NULL, but several call sites used test_bit() on it\nunconditionally.\n\nSwitching to devlink eswitch mode creates representors and runs\notx2_init_hw_resources(), which reaches otx2_pool_aq_init() and oopses\nwhen dereferencing the NULL bitmap. Add NULL checks before every\naf_xdp_zc_qidx test_bit() use in the RSS, ethtool, XSK, and pool init\npaths."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/marvell/octeontx2/nic/otx2_common.c","drivers/net/ethernet/marvell/octeontx2/nic/otx2_ethtool.c","drivers/net/ethernet/marvell/octeontx2/nic/otx2_xsk.c"],"versions":[{"version":"efabce29015189cb5cd8066cf29eb1d754de6c3c","lessThan":"b003d5b4e46ca5033859db601e12d36da24d0e40","status":"affected","versionType":"git"},{"version":"efabce29015189cb5cd8066cf29eb1d754de6c3c","lessThan":"7e33c6bd049b532d2ec4916895ef07e538bed905","status":"affected","versionType":"git"},{"version":"efabce29015189cb5cd8066cf29eb1d754de6c3c","lessThan":"b09a0503c755b6609fad59a84cc7f05b6843a03c","status":"affected","versionType":"git"},{"version":"9bd7273cf1f9c5761d696cca821d25602e8f7009","status":"affected","versionType":"git"},{"version":"6.14.9","lessThan":"6.15","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/marvell/octeontx2/nic/otx2_common.c","drivers/net/ethernet/marvell/octeontx2/nic/otx2_ethtool.c","drivers/net/ethernet/marvell/octeontx2/nic/otx2_xsk.c"],"versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14.9"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b003d5b4e46ca5033859db601e12d36da24d0e40"},{"url":"https://git.kernel.org/stable/c/7e33c6bd049b532d2ec4916895ef07e538bed905"},{"url":"https://git.kernel.org/stable/c/b09a0503c755b6609fad59a84cc7f05b6843a03c"}],"title":"octeontx2-pf: fix NULL deref of af_xdp_zc_qidx on rep setup","x_generator":{"engine":"bippy-1.2.0"}}}}