DEBIAN-CVE-2026-23054
Advisory lineage Upstream: 1 Downstream: 3
Upstream
Downstream
Published: 04 Feb 2026, 17:16
Last modified:15 Jun 2026, 19:06
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
04 Feb 2026, 17:16
Published
Vulnerability first disclosed
15 Jun 2026, 19:06
Last Modified
Vulnerability information updated
Description
In the Linux kernel, the following vulnerability has been resolved: net: hv_netvsc: reject RSS hash key programming without RX indirection table RSS configuration requires a valid RX indirection table. When the device reports a single receive queue, rndis_filter_device_add() does not allocate an indirection table, accepting RSS hash key updates in this state leads to a hang. Fix this by gating netvsc_set_rxfh() on ndc->rx_table_sz and return -EOPNOTSUPP when the table is absent. This aligns set_rxfh with the device capabilities and prevents incorrect behavior.
Affected Systems
- debian•linux
all | all | all | all | < 6.1.162-1 | < 6.12.69-1 | < 6.18.8-1
- debian•linux-6.1
all | < 6.1.162-1~deb11u1