CVE-2026-23070
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23070 is a missing validation vulnerability in the Linux kernel's OcteonTX2 ARM Foundation (AF) driver (octeontx2-af) that can cause kernel panics (denial of service) on affected Marvell OcteonTX hardware. The flaw arises when the kernel accesses firmware-populated data structures (MAC address, link modes, EEPROM data) via the MAC block (CGX/RPM) on boards booted without a MAC block, triggering a memory access violation. Affected versions span Linux kernel 6.9 through 6.18.7, as well as 6.19-rc1 through 6.19-rc6. It was published on February 4, 2026, with patches released on March 18, 2026. The CVSS v3.1 base score is 5.5 (Medium) (Feedly, CVE.org).

Technical details

The root cause is improper input validation (CWE-20) — specifically, the kernel driver fails to verify whether the firmware data structure (fwdata) is valid before accessing it during hardware initialization. On Marvell OcteonTX CN98XX boards booted without a MAC block (CGX/RPM), the rvu_sdp_init function (called from rvu_probe) dereferences an invalid or uninitialized firmware pointer, resulting in a kernel Oops (exception code 0000000096000005) and system crash. Exploitation requires local access to a system running an affected kernel version on the specific hardware platform. The fix adds proper null/validity checks for fwdata before any access, as implemented in kernel commits 4a3dba48 and e343973f (Feedly, kernel.org patch 1, kernel.org patch 2).

Impact

Successful exploitation results in a kernel panic, causing a complete denial of service (system crash) on affected Marvell OcteonTX systems. There is no confidentiality or integrity impact — the vulnerability is limited to availability. Because the crash occurs during system initialization (rvu_probe), affected systems may be rendered unbootable or unstable until the kernel is updated (Feedly).

Indicators of compromise

  • Logs: Kernel log entries containing Internal error: Oops: 0000000096000005 [#1] SMP during system boot or hardware initialization.
  • Logs: Stack traces referencing rvu_sdp_init and rvu_probe in the kernel log (e.g., dmesg or /var/log/kern.log).
  • Logs: Workqueue entries showing kworker processes crashing during work_for_cpu_fn on CPU 0 at boot time.
  • System Behavior: Unexpected system reboots or kernel panics on Marvell OcteonTX CN98XX hardware shortly after boot, particularly during network driver initialization.

Mitigation and workarounds

Update to Linux kernel version 6.18.8 or later, or 6.19-rc7 or later, which include the fix commits 4a3dba48188208e4f66822800e042686784d29d1 and e343973fab43c266a40e4e0dabdc4216db6d5eff. Downstream distributions including SUSE (SUSE-2026-0962-1) and Debian (DSA-6238-1, linux 6.12.85) have issued updated kernel packages. As a temporary workaround for systems that cannot be immediately patched, avoid rebooting affected OcteonTX boards and restrict physical or local access to the hardware until the patch can be applied (Feedly, SUSE Advisory, Debian Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management