Junglewise Threat Intelligence

CVE-2026-90080: Linux kernel octeontx2-pf NULL pointer dereference in AF_XDP

CVE-2026-90080 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Marvell OcteonTX2 network driver in the Linux kernel contains a NULL pointer dereference vulnerability in its AF_XDP (zero-copy socket) support. When switching to devlink eswitch mode or using network representors, the driver attempts to dereference a NULL bitmap without proper validation, causing a kernel panic that disrupts system availability and networking functionality.

Technical details

The vulnerability is a NULL pointer dereference (CWE-476) in the octeontx2-pf driver's AF_XDP zero-copy receive implementation. The `af_xdp_zc_qidx` pointer is allocated only during PF/VF probe for AF_XDP-enabled paths, but is left NULL for representors and non-AF_XDP configurations. Multiple code paths in RSS, ethtool, XSK, and pool initialization routines unconditionally call `test_bit()` on this NULL pointer without validation. The crash occurs when `otx2_init_hw_resources()` is called during representor setup, reaching `otx2_pool_aq_init()`. The fix adds explicit NULL pointer checks before every `test_bit()` operation on `af_xdp_zc_qidx` in four affected code paths. The vulnerability requires local access and CAP_NET_ADMIN privileges to trigger via devlink eswitch mode manipulation. Patches are available in the Linux stable tree.

Affected products

  • Linux Linux kernel 4.20 and later (octeontx2-pf driver affected versions)

Timeline

  • 2026-09-17: disclosed
  • 2026-09-14: patched

References

Related threats