Executive brief
A vulnerability in the Linux kernel's network driver for Texas Instruments Ethernet switches could cause a system crash. The issue occurs during specific error conditions when the system is initializing or shutting down network ports. This could allow a local user to cause a denial-of-service by triggering a kernel panic.
Technical details
A race or error condition in the 'cpsw_new' driver (drivers/net/ethernet/ti/cpsw_new.c) allows 'cpsw_unregister_ports' to attempt to unregister a 'net_device' that failed its initial registration. Specifically, if 'register_netdev' fails for the first MAC in 'cpsw_register_ports', the second MAC's pointer remains in an inconsistent state. An attacker with local access could potentially trigger this error path to cause a kernel oops or panic (Denial of Service). The fix introduces a check for 'ndev->reg_state != NETREG_REGISTERED' before proceeding with unregistration.
Affected products
- Linux Linux Kernel 5.5 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory
- 2026-02-05: patched: Initial upstream patch date