IT

Tracker / CVE-2026-45849

CVE-2026-45849

Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: add missing lock protection in ocelot_port_xmit_inj() ocelot_port_xmit_inj() calls ocelot_can_inject() and ocelot_port_inject_frame() without holding the injection group lock. Both functions contain lockdep_assert_held() for the injection lock, and the correct caller felix_port_deferred_xmit() properly acquires the lock using ocelot_lock_inj_grp() before calling these functions. Add ocelot_lock_inj_grp()/ocelot_unlock_inj_grp() around the register injection path to fix the missing lock protection. The FDMA path is not affected as it uses its own locking mechanism.

Affected products and versions

linux linux_kernel
linux linux_kernel · 6.1.107 → 6.1.165
linux linux_kernel · 6.10.7 → 6.11
linux linux_kernel · 6.11.1 → 6.12.75
linux linux_kernel · 6.13 → 6.18.14
linux linux_kernel · 6.19 → 6.19.4
linux linux_kernel · 6.6.48 → 6.6.128

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References