Executive brief
A vulnerability was identified in the Linux kernel's Ocelot network driver where certain internal functions were being called without proper synchronization locks. This driver is used to manage specific Ethernet switch hardware. If exploited, this could lead to unpredictable system behavior or crashes during network frame transmission, potentially impacting the reliability and availability of the affected networking equipment.
Technical details
A concurrency issue exists in the MSCC Ocelot driver (drivers/net/ethernet/mscc/ocelot_net.c) within the Linux kernel. The function ocelot_port_xmit_inj() invokes ocelot_can_inject() and ocelot_port_inject_frame() without acquiring the required injection group lock. These downstream functions rely on lockdep_assert_held() to ensure thread safety during register injection. An attacker or specific system conditions could trigger a race condition during frame injection, leading to kernel instability. The fix involves wrapping the register injection path with ocelot_lock_inj_grp() and ocelot_unlock_inj_grp() calls. The FDMA path remains unaffected as it utilizes a separate locking mechanism.
Affected products
- Linux Linux Kernel Fixed in 026f6513c5880c2c89e38ad66bbec2868f978605 and related stable backports
Timeline
- 2026-02-08: other: Patch authored
- 2026-05-27: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/026f6513c5880c2c89e38ad66bbec2868f978605
- https://git.kernel.org/stable/c/0b217a40156f497e09dd20d3f7baec40c785f386
- https://git.kernel.org/stable/c/51c32ae7fae14552d79f7139614b77c1bbd57a48
- https://git.kernel.org/stable/c/63da961381e0d979459dede713001f8452364477
- https://git.kernel.org/stable/c/7ac58d8832802ec89baa7539e13e6d58a88cce04
- https://git.kernel.org/stable/c/cc1b179f778f98270bdbbb48d183b4b6427ae198