« Volver al listado

CVE-2026-97966

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

octeontx2-pf: reset HTB scheduler topology before freeing queues

HTB offload programs NIX_AF_TLxX_TOPOLOGY on QoS-allocated scheduler queues via otx2_qos_txschq_set_parent_topology(), but teardown freed those queues without clearing TOPOLOGY. The AF only restores PARENT and SCHEDULE on free, so PRIO_ANCHOR/RR_PRIO settings can survive in the shared scheduler pool and affect later allocations.

Add otx2_qos_reset_schq_topology() and otx2_qos_free_hw_schq() to zero TL4 through TL2 TOPOLOGY before each schq is returned to the AF during hierarchy teardown and cfg rollback.

Leer descripción completaMostrar menos

Skip the aggregation level (TL1): it is a per-tx-link queue shared by the PF, default Tx hierarchy and VFs, and is not freed back to the AF by nix_txschq_free_one().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97966",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5e6808b4c68d7882971514ab3279926eb07c8b2d",
              "lessThan": "16c5c8ea5017952ff14c87626a45359d195dda6f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e6808b4c68d7882971514ab3279926eb07c8b2d",
              "lessThan": "0aa2dd6eaa347c7aab448df0eec0afcfe7489885",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e6808b4c68d7882971514ab3279926eb07c8b2d",
              "lessThan": "621c99be42e3f5cb68a6af9480a255218a761c4e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e6808b4c68d7882971514ab3279926eb07c8b2d",
              "lessThan": "2df186418e17b30b319cf9ff81aad137692ab107",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e6808b4c68d7882971514ab3279926eb07c8b2d",
              "lessThan": "ef39fca8508597fa565cf2be72a884a712fb98af",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/marvell/octeontx2/nic/qos.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/marvell/octeontx2/nic/qos.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:24.413",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0aa2dd6eaa347c7aab448df0eec0afcfe7489885",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/16c5c8ea5017952ff14c87626a45359d195dda6f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2df186418e17b30b319cf9ff81aad137692ab107",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/621c99be42e3f5cb68a6af9480a255218a761c4e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ef39fca8508597fa565cf2be72a884a712fb98af",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: reset HTB scheduler topology before freeing queues\n\nHTB offload programs NIX_AF_TLxX_TOPOLOGY on QoS-allocated scheduler\nqueues via otx2_qos_txschq_set_parent_topology(), but teardown freed\nthose queues without clearing TOPOLOGY.  The AF only restores PARENT and\nSCHEDULE on free, so PRIO_ANCHOR/RR_PRIO settings can survive in the\nshared scheduler pool and affect later allocations.\n\nAdd otx2_qos_reset_schq_topology() and otx2_qos_free_hw_schq() to zero\nTL4 through TL2 TOPOLOGY before each schq is returned to the AF during\nhierarchy teardown and cfg rollback.  Skip the aggregation level (TL1):\nit is a per-tx-link queue shared by the PF, default Tx hierarchy and VFs,\nand is not freed back to the AF by nix_txschq_free_one()."
    }
  ],
  "lastModified": "2026-10-03T11:18:21.490",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}