CVE-2026-97435

Summary

In the Linux kernel, the following vulnerability has been resolved:

net: dsa: sja1105: flower: reject cross-chip redirect

dsa_port_from_netdev() may return a valid port from a different switch chip. Programming another chip's port index into the local hardware causes redirection to the wrong port, or an out-of-bounds access if the index exceeds the local chip's port count.

Apply a minimal fix that adds a check to catch this case and adjusts the extack message. When cls->common.skip_sw is not set, the operation could instead redirect to the upstream port and let the software or upstream switch(es) handle the forward, but that is not addressed here.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxdfacc5a23e227cabdff41b6202f510398e90d36b < c999cc39775381b68ed66eae57c1425452672c0faffected
LinuxLinuxdfacc5a23e227cabdff41b6202f510398e90d36b < abd7511e12b231798332afa04ed9bee9e84f9445affected
LinuxLinuxdfacc5a23e227cabdff41b6202f510398e90d36b < cfa5274a5dc2a23b957da5dc806d2ac0c7a66af0affected
LinuxLinux5.8affected
LinuxLinux0 < 5.8unaffected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References