Bug 2540521 (CVE-2026-97435) - CVE-2026-97435 kernel: net: dsa: sja1105: flower: reject cross-chip redirect
Summary: CVE-2026-97435 kernel: net: dsa: sja1105: flower: reject cross-chip redirect
Keywords:
Status: NEW
Alias: CVE-2026-97435
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-24 17:06 UTC by OSIDB Bzimport
Modified: 2026-09-29 13:46 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-24 17:06:34 UTC
In the Linux kernel, the following vulnerability has been resolved:

net: dsa: sja1105: flower: reject cross-chip redirect

dsa_port_from_netdev() may return a valid port from a different switch
chip. Programming another chip's port index into the local hardware
causes redirection to the wrong port, or an out-of-bounds access if the
index exceeds the local chip's port count.

Apply a minimal fix that adds a check to catch this case and adjusts the
extack message. When cls->common.skip_sw is not set, the operation could
instead redirect to the upstream port and let the software or upstream
switch(es) handle the forward, but that is not addressed here.


Note You need to log in before you can comment on or make changes to this bug.